Description
Stored cross-site scripting vulnerability in the Create event section in Pandora FMS Console v766 and lower. An attacker typically exploits this vulnerability by injecting XSS payloads on popular pages of a site or passing a link to a victim, tricking them into viewing the page that contains the stored XSS payload.
No analysis available yet.
Remediation
Vendor Solution
fixed in v767
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-50139 | Stored cross-site scripting vulnerability in the Create event section in Pandora FMS Console v766 and lower. An attacker typically exploits this vulnerability by injecting XSS payloads on popular pages of a site or passing a link to a victim, tricking them into viewing the page that contains the stored XSS payload. |
References
History
Tue, 18 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-03-18T19:20:10.880Z
Reserved: 2022-12-13T00:00:00.000Z
Link: CVE-2022-47372
Updated: 2024-08-03T14:55:07.199Z
Status : Modified
Published: 2023-02-15T04:15:10.987
Modified: 2024-11-21T07:31:50.883
Link: CVE-2022-47372
No data.
OpenCVE Enrichment
No data.
EUVD