PT-2023-15288 · Unknown · Pandora Fms Console

Gaurish Kauthankar

·

Published

2023-02-15

·

Updated

2023-02-23

·

CVE-2022-47373

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Pandora FMS Console versions prior to v767
Description The issue arises from a Reflected Cross Site Scripting vulnerability in the Search Functionality of the Module Library. This vulnerability is triggered by the forget password functionality, where the username parameter lacks proper input validation and sanitization, allowing the execution of malicious JavaScript payloads.
Recommendations For versions prior to v767, update to a version that includes proper input validation and sanitization for the username parameter in the forget password functionality. As a temporary workaround, consider restricting access to the forget password functionality until a patch is available.

Exploit

Fix

CSRF

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-47373

Affected Products

Pandora Fms Console