PT-2021-21312 · Unknown · Pandora Fms

K4M1Ll0

+1

·

Published

2021-11-03

·

Updated

2021-11-04

·

CVE-2021-36698

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pandora FMS versions through 755
Description The issue allows for XSS via a new Event Filter with a crafted name. This can be exploited when a user creates a new Event Filter with a specifically designed name, potentially leading to cross-site scripting attacks.
Recommendations For versions through 755, consider disabling the creation of new Event Filters until a patch is available to prevent potential XSS attacks. Restrict access to the Event Filter feature to minimize the risk of exploitation. Avoid using crafted names in the Event Filter to prevent the issue.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36698

Affected Products

Pandora Fms