Description
Cross-site Scripting (XSS) vulnerability in Visual Console Module of Pandora FMS could be used to hijack admin users session cookie values, carry out phishing attacks, etc. This issue affects Pandora FMS v767 version and prior versions on all platforms.
No analysis available yet.
Remediation
Vendor Solution
Fixed in v769
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-28532 | Cross-site Scripting (XSS) vulnerability in Visual Console Module of Pandora FMS could be used to hijack admin users session cookie values, carry out phishing attacks, etc. This issue affects Pandora FMS v767 version and prior versions on all platforms. |
References
History
Fri, 27 Sep 2024 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-09-27T21:57:03.260Z
Reserved: 2023-01-25T13:49:34.265Z
Link: CVE-2023-24514
Updated: 2024-08-02T10:56:04.297Z
Status : Modified
Published: 2023-08-22T19:16:34.393
Modified: 2024-11-21T07:48:01.730
Link: CVE-2023-24514
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD