PT-2023-14665 · Artica · Artica Pandora Fms
Damodar Naik
·
Published
2023-02-15
·
Updated
2023-10-18
·
CVE-2022-45436
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Artica PFMS Pandora FMS version v765
Description
The issue allows Cross-Site Scripting (XSS) due to improper neutralization of input during web page generation. As a manager privilege user, an attacker can create a network map containing a malicious name, which acts as an XSS payload. Once created, if an admin user clicks on the edit network maps, the XSS payload will be executed. This could potentially be used for stealing admin users' cookie values.
Recommendations
For Artica PFMS Pandora FMS version v765, as a temporary workaround, consider restricting access to the network map creation feature for manager privilege users until a patch is available. Additionally, restrict the ability to edit network maps for admin users to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Artica Pandora Fms