PT-2022-17777 · Unknown · Pandora Fms

Published

2022-08-01

·

Updated

2022-08-05

·

CVE-2022-26309

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pandora FMS version 7.0NG.759
Description The issue allows Cross-Site Request Forgery in Bulk operation, specifically in the User operation, resulting in elevation of privilege to the Administrator group.
Recommendations For Pandora FMS version 7.0NG.759, as a temporary workaround, consider disabling the Bulk operation feature in User operation until a patch is available. Restrict access to the Administrator group to minimize the risk of exploitation. Avoid using the Bulk operation feature in the User operation until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-26309

Affected Products

Pandora Fms