VYPR

Pandorafms

by Pandorafms

Source repositories

CVEs (50)

  • CVE-2021-46679MedAug 5, 2022
    risk 0.26cvss 4.0epss 0.00

    A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via service elements.

  • CVE-2021-46678MedAug 5, 2022
    risk 0.26cvss 4.0epss 0.00

    A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the service name field.

  • CVE-2021-46677MedAug 5, 2022
    risk 0.26cvss 4.0epss 0.00

    A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the event filter name field.

  • CVE-2021-46676MedAug 5, 2022
    risk 0.26cvss 4.0epss 0.00

    A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the transactional maps name field.

  • CVE-2023-41814LowDec 29, 2023
    risk 0.24cvss 3.7epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). Through an HTML payload (iframe tag) it is possible to carry out XSS attacks when the user receiving the messages opens…

  • CVE-2022-26309LowAug 1, 2022
    risk 0.24cvss 3.7epss 0.00

    Pandora FMS v7.0NG.759 allows Cross-Site Request Forgery in Bulk operation (User operation) resulting in elevation of privilege to Administrator group.

  • CVE-2022-26308LowAug 1, 2022
    risk 0.24cvss 3.7epss 0.00

    Pandora FMS v7.0NG.760 and below allows an improper access control in Configuration (Credential store) where a user with the role of Operator (Write) could create, delete, view existing keys which are outside the intended role.

  • CVE-2022-2059LowJul 25, 2022
    risk 0.23cvss 3.5epss 0.00

    In Pandora FMS v7.0NG.761 and below, in the agent creation section, the alias parameter is vulnerable to a Stored Cross Site-Scripting. This vulnerability can be exploited by an attacker with administrator privileges logged in the system.

  • CVE-2022-2032LowJul 25, 2022
    risk 0.23cvss 3.5epss 0.00

    In Pandora FMS v7.0NG.761 and below, in the file manager section, the dirname parameter is vulnerable to a Stored Cross Site-Scripting. This vulnerability can be exploited by an attacker with administrator privileges logged in the system.

  • CVE-2023-41813LowDec 29, 2023
    risk 0.20cvss 3.0epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). Allows you to edit the Web Console user notification options. This issue affects Pandora FMS: from 700 through 774.

Page 3 of 3