PT-2022-12896 · Unknown · Pandora Fms
Published
2022-08-05
·
Updated
2022-08-07
·
CVE-2021-46676
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Pandora FMS versions 756 and below
Description
A XSS issue exists that allows an attacker to perform javascript code executions via the
transactional maps name field. This enables the execution of malicious scripts.Recommendations
For Pandora FMS versions 756 and below, update to a version above 756 to resolve the issue. As a temporary workaround, consider restricting access to the transactional maps name field to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pandora Fms