PT-2020-12822 · Artica · Pandora Fms

Applebois

·

Published

2020-07-13

·

Updated

2023-01-27

·

CVE-2020-11749

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pandora FMS versions 7.0 NG through 746
Description The issue concerns Multiple XSS vulnerabilities in different browser views of Pandora FMS. It can be triggered by a network administrator scanning a SNMP device, leading to Cross Site Scripting (XSS) that allows arbitrary code execution, potentially enabling Remote Code Execution as root or apache2.
Recommendations For Pandora FMS versions 7.0 NG through 746, consider disabling the SNMP scanning feature until a patch is available to prevent potential exploitation of the XSS vulnerability. Restrict access to the browser views where the XSS vulnerability is present to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-11749

Affected Products

Pandora Fms