PT-2023-15288 · Unknown · Pandora Fms Console
Gaurish Kauthankar
·
Published
2023-02-15
·
Updated
2023-02-23
·
CVE-2022-47373
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Pandora FMS Console versions prior to v767
Description
The issue arises from a Reflected Cross Site Scripting vulnerability in the Search Functionality of the Module Library. This vulnerability is triggered by the forget password functionality, where the
username parameter lacks proper input validation and sanitization, allowing the execution of malicious JavaScript payloads.Recommendations
For versions prior to v767, update to a version that includes proper input validation and sanitization for the
username parameter in the forget password functionality.
As a temporary workaround, consider restricting access to the forget password functionality until a patch is available.Exploit
Fix
CSRF
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pandora Fms Console