Reflected Cross Site Scripting in Search Functionality of Module Library in Pandora FMS Console v766 and lower. This vulnerability arises on the forget password functionality in which parameter username does not proper input validation/sanitization thus results in executing malicious JavaScript payload.
References
Link | Resource |
---|---|
https://github.com/Argonx21/CVE-2022-47373 | Third Party Advisory |
https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/ | Vendor Advisory |
https://github.com/Argonx21/CVE-2022-47373 | Third Party Advisory |
https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/ | Vendor Advisory |
Configurations
History
21 Nov 2024, 07:31
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.4 |
References | () https://github.com/Argonx21/CVE-2022-47373 - Third Party Advisory | |
References | () https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/ - Vendor Advisory |
Information
Published : 2023-02-15 04:15
Updated : 2024-11-21 07:31
NVD link : CVE-2022-47373
Mitre link : CVE-2022-47373
CVE.ORG link : CVE-2022-47373
JSON object : View
Products Affected
pandorafms
- pandora_fms