PT-2021-21312 · Unknown · Pandora Fms
K4M1Ll0
+1
·
Published
2021-11-03
·
Updated
2021-11-04
·
CVE-2021-36698
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Pandora FMS versions through 755
Description
The issue allows for XSS via a new Event Filter with a crafted name. This can be exploited when a user creates a new Event Filter with a specifically designed name, potentially leading to cross-site scripting attacks.
Recommendations
For versions through 755, consider disabling the creation of new Event Filters until a patch is available to prevent potential XSS attacks. Restrict access to the Event Filter feature to minimize the risk of exploitation. Avoid using crafted names in the Event Filter to prevent the issue.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pandora Fms