Vulnerabilities > Pandorafms
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-10-22 | CVE-2024-35308 | Path Traversal vulnerability in Pandorafms Pandora FMS A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. This issue affects Pandora FMS: from 700 through <777.3. | 8.8 |
2024-10-22 | CVE-2024-9987 | SQL Injection vulnerability in Pandorafms Pandora FMS A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv functionality. This issue affects Pandora FMS: from 700 through <777.3. | 8.8 |
2023-12-29 | CVE-2023-41813 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). Allows you to edit the Web Console user notification options. This issue affects Pandora FMS: from 700 through 774. | 6.1 |
2023-12-29 | CVE-2023-41814 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). | 6.1 |
2023-12-29 | CVE-2023-41815 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). Malicious code could be executed in the File Manager section. This issue affects Pandora FMS: from 700 through 774. | 6.1 |
2023-12-29 | CVE-2023-44088 | SQL Injection vulnerability in Pandorafms Pandora FMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitrary SQL queries were allowed to be executed using any account with low privileges. This issue affects Pandora FMS: from 700 through 774. | 8.8 |
2023-12-29 | CVE-2023-44089 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). It was possible to execute malicious JS code on Visual Consoles. This issue affects Pandora FMS: from 700 through 774. | 6.1 |
2023-10-03 | CVE-2023-0828 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS Cross-site Scripting (XSS) vulnerability in Syslog Section of Pandora FMS allows attacker to cause that users cookie value will be transferred to the attackers users server. | 6.1 |
2023-10-03 | CVE-2023-24518 | Cross-Site Request Forgery (CSRF) vulnerability in Pandorafms Pandora FMS A Cross-site Request Forgery (CSRF) vulnerability in Pandora FMS allows an attacker to force authenticated users to send a request to a web application they are currently authenticated against. | 7.1 |
2023-08-22 | CVE-2023-24514 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS Cross-site Scripting (XSS) vulnerability in Visual Console Module of Pandora FMS could be used to hijack admin users session cookie values, carry out phishing attacks, etc. | 6.1 |