Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Artica PFMS Pandora FMS v765 on all allows Cross-Site Scripting (XSS). A user with edition privileges can create a Payload in the reporting dashboard module. An admin user can observe the Payload without interaction and attacker can get information.
No analysis available yet.
Remediation
Vendor Solution
fixed in v766
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-48309 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Artica PFMS Pandora FMS v765 on all allows Cross-Site Scripting (XSS). A user with edition privileges can create a Payload in the reporting dashboard module. An admin user can observe the Payload without interaction and attacker can get information. |
References
History
Tue, 18 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-03-18T19:20:57.800Z
Reserved: 2022-11-15T00:00:00.000Z
Link: CVE-2022-45437
Updated: 2024-08-03T14:09:57.064Z
Status : Modified
Published: 2023-02-15T04:15:10.893
Modified: 2024-11-21T07:29:15.567
Link: CVE-2022-45437
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD