Impact
The vulnerability arises from missing input validation and output encoding on the directory name parameter in Pandora FMS’s File Manager Create Directory function. This allows an attacker to inject malicious script code that is stored in the system and executed when the directory listing is viewed. The resulting stored XSS can lead to arbitrary script execution, session hijacking, or defacement of the web interface, compromising both confidentiality and integrity of user data.
Affected Systems
Pandora FMS is affected for all released versions from 777 onward. The vendor has provided a fix in v800.5 and v805, which patch the directory name handling logic.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity level. The EPSS score is not available, so the current exploitation probability is unknown, but the vulnerability can be deployed without further user interaction once the attacker can submit a directory name. The vulnerability is not listed in the CISA KEV catalog, though it has a medium likelihood of exploitation in environments where users have permission to create directories in the File Manager.
OpenCVE Enrichment