Cross-site Scripting (XSS) vulnerability in the Pandora FMS Special Days component allows an attacker to use it to steal the session cookie value of admin users easily with little user interaction. This issue affects Pandora FMS v767 version and prior versions on all platforms.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-28534 | Cross-site Scripting (XSS) vulnerability in the Pandora FMS Special Days component allows an attacker to use it to steal the session cookie value of admin users easily with little user interaction. This issue affects Pandora FMS v767 version and prior versions on all platforms. |
Fixes
Solution
Fixed in v769
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-09-06T14:13:21.668Z
Reserved: 2023-01-25T13:49:34.265Z
Link: CVE-2023-24516
Updated: 2024-08-02T10:56:04.230Z
Status : Modified
Published: 2023-08-22T19:16:34.557
Modified: 2024-11-21T07:48:02.007
Link: CVE-2023-24516
No data.
OpenCVE Enrichment
No data.
EUVD