Description
A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 777 onwards.
Published: 2026-10-01
Score: 7.4 High
EPSS: n/a
KEV: No
Impact: Admin Account Takeover
Action: Patch Now
AI Analysis

Impact

The vulnerability consists of a chained CSRF attack combined with an unrestricted SVG file upload in the File Manager module, which results in stored Cross‑Site Scripting. This flaw allows an attacker to inject malicious JavaScript that is executed in the context of an administrator's browser session, enabling session cookie exfiltration and the takeover of the administrator account. The weakness is a classic Cross‑Site Scripting flaw (CWE‑79) compounded by the lack of CSRF protection (CWE‑352).

Affected Systems

The issue affects Pandora FMS applications from version 777 onwards. The File Manager component is the entry point. The vendor has released fixes in versions 800.5 and 805, which correct the unchecked SVG upload and eliminate the CSRF bypass.

Risk and Exploitability

The CVSS score of 7.4 indicates a high likelihood of significant impact if exploited. The EPSS score is not available, and the flaw is not listed in CISA’s KEV, so active exploitation data is limited. However, exploitation is feasible because the attacker only needs to craft a malicious site that the victim visits while authenticated; there is no requirement for additional credentials or privileged access. Once the stored XSS payload is executed, the attacker can access session cookies or directly hijack the administrator account.

Generated by OpenCVE AI on October 1, 2026 at 10:34 UTC.

Remediation

Vendor Solution

Fixed v800.5 and v805


OpenCVE Recommended Actions

  • Upgrade to version 800.5 or 805 to apply the fix for the CSRF and unrestricted SVG upload issue.
  • If immediate upgrade is not feasible, disable SVG uploads in the File Manager or restrict uploads to safe file types to block the stored XSS vector.
  • Ensure CSRF protection is enabled for all file upload operations and audit the File Manager configuration for proper input validation.

Generated by OpenCVE AI on October 1, 2026 at 10:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Pandora Fms
Pandora Fms pandora Fms
Vendors & Products Pandora Fms
Pandora Fms pandora Fms

Thu, 01 Oct 2026 09:45:00 +0000

Type Values Removed Values Added
Description A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 777 onwards.
Title CSRF Bypass Leading to Stored Cross-Site Scripting via Unrestricted SVG Upload in File Manager
Weaknesses CWE-352
CWE-79
References
Metrics cvssV4_0

{'score': 7.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/S:N/AU:Y/R:U/V:C/RE:M/U:Amber'}


Subscriptions

Pandora Fms Pandora Fms
cve-icon MITRE

Status: PUBLISHED

Assigner: PandoraFMS

Published:

Updated: 2026-10-01T15:01:25.546Z

Reserved: 2026-07-21T06:52:17.076Z

Link: CVE-2026-64946

cve-icon Vulnrichment

Updated: 2026-10-01T15:01:22.755Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T10:17:15.763

Modified: 2026-10-01T15:17:30.940

Link: CVE-2026-64946

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T10:45:07Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')