In Pandora FMS v7.0NG.761 and below, in the file manager section, the dirname parameter is vulnerable to a Stored Cross Site-Scripting. This vulnerability can be exploited by an attacker with administrator privileges logged in the system.
Solution:
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/ | vendor advisory |
https://www.incibe.es/en/cve-assignment-publication/coordinated-cves | third party advisory |