Unknown · Pandora Fms · CVE-2023-24516
**Name of the Vulnerable Software and Affected Versions**
Pandora FMS versions prior to v767
**Description**
A Cross-site Scripting (XSS) issue in the Special Days component allows an attacker to steal the session cookie value of admin users with little user interaction.
**Recommendations**
For versions prior to v767, update to version v767 or later to resolve the issue. As a temporary workaround, consider restricting access to the Special Days component to minimize the risk of exploitation.