PT-2023-16553 · Unknown · Pandora Fms

CVE-2023-0828

·

Publicado

2023-10-03

·

Atualizado

2023-10-04

CVSS v3.1

6.7

Média

VetorAV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Pandora FMS version 7.67 and prior versions
Description A Cross-site Scripting (XSS) issue in the Syslog Section of Pandora FMS allows an attacker to transfer a user's cookie value to the attacker's server.
Recommendations For Pandora FMS version 7.67 and prior versions, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to the Syslog Section until a patch is available.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-0828

Produtos afetados

Pandora Fms