Impact
The vulnerability consists of a chained CSRF attack combined with an unrestricted SVG file upload in the File Manager module, which results in stored Cross‑Site Scripting. This flaw allows an attacker to inject malicious JavaScript that is executed in the context of an administrator's browser session, enabling session cookie exfiltration and the takeover of the administrator account. The weakness is a classic Cross‑Site Scripting flaw (CWE‑79) compounded by the lack of CSRF protection (CWE‑352).
Affected Systems
The issue affects Pandora FMS applications from version 777 onwards. The File Manager component is the entry point. The vendor has released fixes in versions 800.5 and 805, which correct the unchecked SVG upload and eliminate the CSRF bypass.
Risk and Exploitability
The CVSS score of 7.4 indicates a high likelihood of significant impact if exploited. The EPSS score is not available, and the flaw is not listed in CISA’s KEV, so active exploitation data is limited. However, exploitation is feasible because the attacker only needs to craft a malicious site that the victim visits while authenticated; there is no requirement for additional credentials or privileged access. Once the stored XSS payload is executed, the attacker can access session cookies or directly hijack the administrator account.
OpenCVE Enrichment