A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the event filter name field.
Solution:
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/ | vendor advisory |
https://www.incibe.es/en/cve-assignment-publication/coordinated-cves | third party advisory |