Impact
Cross‑Site Request Forgery vulnerability permits deletion of event responses via forged GET requests when an authenticated administrator visits a malicious page. Attackers can remove event responses, compromising event integrity and audit trails, representing an unauthorized data deletion flaw (CWE‑352).
Affected Systems
Pandora FMS versions 777 and later are affected until patched to v8.05 or v8.00.5, which includes the fix.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. EPSS is not reported, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. However, because the flaw requires an authenticated administrator to be tricked into visiting a malicious site, attackers can achieve unauthorized data deletion; exploitation is straightforward once the admin is lured, making the risk significant for entities relying on Pandora FMS event logging.
OpenCVE Enrichment