CVE-2019-12954: SolarWinds Network Performance Monitor Orion Platform 2018 Netpath
Medium severity, CVSS 5.4. EPSS: 1.4% chance of exploitation in the next 30 days.
SolarWinds Network Performance Monitor (Orion Platform 2018, NPM 12.3, NetPath 1.1.3) allows XSS by authenticated users via a crafted onerror attribute of a VIDEO element in an action for an ALERT.
Affected products
- SolarWinds Network Performance Monitor Orion Platform 2018 Netpath: version 1.1.3 only
- SolarWinds Network Performance Monitor Orion Platform 2018 Npm: version 12.3 only
Published 2020-02-17. Last modified 2026-06-17.