Filtered by vendor Pandorafms
Subscriptions
Filtered by product Pandora Fms
Subscriptions
Total
46 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2023-41814 | 1 Pandorafms | 1 Pandora Fms | 2024-08-02 | 3.7 Low |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). Through an HTML payload (iframe tag) it is possible to carry out XSS attacks when the user receiving the messages opens their notifications. This issue affects Pandora FMS: from 700 through 774. | ||||
CVE-2023-41813 | 1 Pandorafms | 1 Pandora Fms | 2024-08-02 | 3 Low |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). Allows you to edit the Web Console user notification options. This issue affects Pandora FMS: from 700 through 774. | ||||
CVE-2023-41815 | 1 Pandorafms | 1 Pandora Fms | 2024-08-02 | 7.5 High |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). Malicious code could be executed in the File Manager section. This issue affects Pandora FMS: from 700 through 774. | ||||
CVE-2023-2807 | 1 Pandorafms | 1 Pandora Fms | 2024-08-02 | 6.4 Medium |
Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a password reset process for any user account without proper authentication. This issue affects PandoraFMS v771 and prior versions on all platforms. | ||||
CVE-2024-35304 | 1 Pandorafms | 1 Pandora Fms | 2024-08-02 | N/A |
System command injection through Netflow function due to improper input validation, allowing attackers to execute arbitrary system commands. This issue affects Pandora FMS: from 700 through <777. | ||||
CVE-2024-35307 | 1 Pandorafms | 1 Pandora Fms | 2024-08-02 | N/A |
Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to execute arbitrary code on the server. This issue affects Pandora FMS: from 700 through <777. |