PT-2023-15288 · Unknown · Pandora Fms Console

Gaurish Kauthankar

·

Publicado

2023-02-15

·

Atualizado

2023-02-23

·

CVE-2022-47373

CVSS v3.1

6.4

Média

VetorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Pandora FMS Console versions prior to v767
Description The issue arises from a Reflected Cross Site Scripting vulnerability in the Search Functionality of the Module Library. This vulnerability is triggered by the forget password functionality, where the username parameter lacks proper input validation and sanitization, allowing the execution of malicious JavaScript payloads.
Recommendations For versions prior to v767, update to a version that includes proper input validation and sanitization for the username parameter in the forget password functionality. As a temporary workaround, consider restricting access to the forget password functionality until a patch is available.

Exploit

Correção

CSRF

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-47373

Produtos afetados

Pandora Fms Console