vendor:
Pandora FMS
by:
Matthew Aberegg
8.8
CVSS
HIGH
Persistent Cross-Site Scripting
79
CWE
Product Name: Pandora FMS
Affected Version From: Pandora FMS 7.0 NG 749
Affected Version To: Pandora FMS 7.0 NG 749
Patch Exists: Yes
Related CWE: N/A
CPE: a:pandorafms:pandora_fms:7.0_ng_749
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 18.04
2020
Pandora FMS 7.0 NG 749 – Multiple Persistent Cross-Site Scripting Vulnerabilities
A persistent cross-site scripting vulnerability exists in the 'Edit OS' and 'Private Enterprise Numbers' functionalities of Pandora FMS. Vulnerable parameters include 'name', 'description', 'manufacturer' and 'description'.
Mitigation:
The vendor has released patches for both vulnerabilities. The patch for the 'Edit OS' vulnerability can be found at https://github.com/pandorafms/pandorafms/commit/58f521e8b570802fa33c75f99586e5b01b06731b and the patch for the 'Private Enterprise Numbers' vulnerability can be found at https://github.com/pandorafms/pandorafms/commit/b9b94e1382f6e340fd9f3136972cca4373f00eb0.