vendor:
PandoraFMS
by:
Emre ÖVÜNÇ
8.8
CVSS
HIGH
Persistent Cross-Site Scripting
79
CWE
Product Name: PandoraFMS
Affected Version From: 7.0NG747
Affected Version To: 7.0NG747
Patch Exists: YES
Related CWE: N/A
CPE: a:pandorafms:pandorafms:7.0ng747
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows/Linux/ISO
2020
PandoraFMS NG747 7.0 – ‘filename’ Persistent Cross-Site Scripting
A stored cross-site scripting (XSS) in Pandora FMS 7.0 NG 747 can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page. To exploit vulnerability, someone could use a POST request to '/pandora_console/index.php' by manipulating 'filename' parameter in the request body to impact users who open a maliciously crafted link or third-party web page.
Mitigation:
Upgrade to the latest version of Pandora FMS 7.0 NG 747.