CVE-2021-35234

Publication date

2021-12-20 20:08:25

Family

SolarWinds

State

PUBLISHED

Description

Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation. An attacker with low-user privileges may steal password hashes and password salt information.