← Vulnerability feed

Vulnerability record · CVE-2023-50395 · published 6 February 2024

CVE-2023-50395: Solarwinds platform sql injection vulnerability

Solarwinds · Solarwinds Platform

SQL Injection Remote Code Execution Vulnerability was found using an update statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited

8.0 CVSS 3.1 High EPSS 1.6% · top 25.5% CWE-89 · SQL injection
8.0CVSS 3.1 base score
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

SQL Injection Remote Code Execution Vulnerability was found using an update statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-50395 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-52606Solarwinds platform server-side request forgery (ssrf) vulnerabilitySolarWinds Platform is affected by server-side request forgery vulnerability. Proper input sanitation was not applied allowing for the possibility of…EPSS 2.5%8.8CVE-2023-40056Solarwinds platform sql injection vulnerabilitySQL Injection Remote Code Vulnerability was found in the SolarWinds Platform. This vulnerability can be exploited with a low privileged account.EPSS 4.8%8.8CVE-2023-40061Solarwinds platform improper input validation vulnerability Insecure job execution mechanism vulnerability. This vulnerability can lead to other attacks as a result.EPSS 0.42%8.8CVE-2023-40062Solarwinds platform improper input validation vulnerabilitySolarWinds Platform Incomplete List of Disallowed Inputs Remote Code Execution Vulnerability. If executed, this vulnerability would allow a low-privi…EPSS 2.7%8.0CVE-2023-35188Solarwinds platform sql injection vulnerabilitySQL Injection Remote Code Execution Vulnerability was found using a create statement in the SolarWinds Platform. This vulnerability requires user aut…EPSS 1.5%7.8CVE-2024-45710Solarwinds platform uncontrolled search path element vulnerabilitySolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This requires a low privilege acc…EPSS 0.28%7.5CVE-2024-28999Solarwinds platform race condition vulnerabilityThe SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console.EPSS 14%7.5CVE-2024-28996Solarwinds platform sql injection vulnerabilityThe SolarWinds Platform was determined to be affected by a SWQL Injection Vulnerability. Attack complexity is high for this vulnerability.  EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2023-50395), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.