vendor:
PandoraFMS
by:
AppleBois
9
CVSS
CRITICAL
Persistent Cross-Site Scripting
79
CWE
Product Name: PandoraFMS
Affected Version From: 7xx
Affected Version To: 746
Patch Exists: NO
Related CWE: CVE-2020-11749
CPE: a:pandorafms:pandorafms:7.0NG
Platforms Tested:
2020
PandoraFMS 7.0 NG 746 – Persistent Cross-Site Scripting
By asking network administrator to scan SNMP device to trigger Cross Site Scripting(XSS), we can call a remote JavaScript file to execute arbitrary code to reach Remote Code Execution on PandoraFMS.
Mitigation:
Apply the patch provided by the vendor.