CVE-2019-12954: SolarWinds Network Performance Monitor Orion Platform 2018 Netpath

Medium severity, CVSS 5.4. EPSS: 1.4% chance of exploitation in the next 30 days.

SolarWinds Network Performance Monitor (Orion Platform 2018, NPM 12.3, NetPath 1.1.3) allows XSS by authenticated users via a crafted onerror attribute of a VIDEO element in an action for an ALERT.

Affected products

  • SolarWinds Network Performance Monitor Orion Platform 2018 Netpath: version 1.1.3 only
  • SolarWinds Network Performance Monitor Orion Platform 2018 Npm: version 12.3 only

Published 2020-02-17. Last modified 2026-06-17.