PT-2020-12822 · Artica · Pandora Fms
Applebois
·
Published
2020-07-13
·
Updated
2023-01-27
·
CVE-2020-11749
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pandora FMS versions 7.0 NG through 746
Description
The issue concerns Multiple XSS vulnerabilities in different browser views of Pandora FMS. It can be triggered by a network administrator scanning a SNMP device, leading to Cross Site Scripting (XSS) that allows arbitrary code execution, potentially enabling Remote Code Execution as root or apache2.
Recommendations
For Pandora FMS versions 7.0 NG through 746, consider disabling the SNMP scanning feature until a patch is available to prevent potential exploitation of the XSS vulnerability. Restrict access to the browser views where the XSS vulnerability is present to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pandora Fms