Vulnerabilities > Pandorafms
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-01-27 | CVE-2022-43979 | Path Traversal vulnerability in Pandorafms Pandora FMS There is a Path Traversal that leads to a Local File Inclusion in Pandora FMS v764. | 9.8 |
2023-01-27 | CVE-2022-43980 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS There is a stored cross-site scripting vulnerability in Pandora FMS v765 in the network maps editing functionality. | 5.4 |
2022-08-05 | CVE-2021-46676 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the transactional maps name field. | 6.1 |
2022-08-05 | CVE-2021-46677 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the event filter name field. | 6.1 |
2022-08-05 | CVE-2021-46678 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the service name field. | 6.1 |
2022-08-05 | CVE-2021-46679 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via service elements. | 6.1 |
2022-08-05 | CVE-2021-46680 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the module form name field. | 6.1 |
2022-08-01 | CVE-2022-26308 | Unspecified vulnerability in Pandorafms Pandora FMS Pandora FMS v7.0NG.760 and below allows an improper access control in Configuration (Credential store) where a user with the role of Operator (Write) could create, delete, view existing keys which are outside the intended role. | 5.4 |
2022-08-01 | CVE-2022-26309 | Cross-Site Request Forgery (CSRF) vulnerability in Pandorafms Pandora FMS Pandora FMS v7.0NG.759 allows Cross-Site Request Forgery in Bulk operation (User operation) resulting in elevation of privilege to Administrator group. | 8.8 |
2022-08-01 | CVE-2022-26310 | Unspecified vulnerability in Pandorafms Pandora FMS Pandora FMS v7.0NG.760 and below allows an improper authorization in User Management where any authenticated user with access to the User Management module could create, modify or delete any user with full admin privilege. | 8.8 |