SolarWinds Database Performance Analyzer 11.1.457 contains a reflected cross-site scripting vulnerability in its idcStateError component, where the page parameter is reflected into the HREF of the ‘Try Again’ Button on the page, aka a /iwc/idcStateError.iwc?page= URI.
View the template here CVE-2018-19386.yaml
References:
https://github.com/Elsfa7-110/kenzer-templates