Vulnerabilities > Pandorafms
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-01-27 | CVE-2022-43980 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS There is a stored cross-site scripting vulnerability in Pandora FMS v765 in the network maps editing functionality. | 5.4 |
2022-08-05 | CVE-2021-46676 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the transactional maps name field. | 6.1 |
2022-08-05 | CVE-2021-46677 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the event filter name field. | 6.1 |
2022-08-05 | CVE-2021-46678 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the service name field. | 6.1 |
2022-08-05 | CVE-2021-46679 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via service elements. | 6.1 |
2022-08-05 | CVE-2021-46680 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the module form name field. | 6.1 |
2022-08-01 | CVE-2022-26308 | Unspecified vulnerability in Pandorafms Pandora FMS Pandora FMS v7.0NG.760 and below allows an improper access control in Configuration (Credential store) where a user with the role of Operator (Write) could create, delete, view existing keys which are outside the intended role. | 5.4 |
2022-08-01 | CVE-2022-26309 | Cross-Site Request Forgery (CSRF) vulnerability in Pandorafms Pandora FMS Pandora FMS v7.0NG.759 allows Cross-Site Request Forgery in Bulk operation (User operation) resulting in elevation of privilege to Administrator group. | 8.8 |
2022-08-01 | CVE-2022-26310 | Unspecified vulnerability in Pandorafms Pandora FMS Pandora FMS v7.0NG.760 and below allows an improper authorization in User Management where any authenticated user with access to the User Management module could create, modify or delete any user with full admin privilege. | 8.8 |
2022-07-26 | CVE-2022-1648 | Path Traversal vulnerability in Pandorafms Pandora FMS Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intended images directory which is restricted to execute the .php file. | 7.2 |