Vulnerabilities > Pandorafms > Pandora FMS > 7.0.ng.761

DATE CVE VULNERABILITY TITLE RISK
2023-10-03 CVE-2023-0828 Cross-site Scripting vulnerability in Pandorafms Pandora FMS
Cross-site Scripting (XSS) vulnerability in Syslog Section of Pandora FMS allows attacker to cause that users cookie value will be transferred to the attackers users server.
network
low complexity
pandorafms CWE-79
6.1
2023-10-03 CVE-2023-24518 Cross-Site Request Forgery (CSRF) vulnerability in Pandorafms Pandora FMS
A Cross-site Request Forgery (CSRF) vulnerability in Pandora FMS allows an attacker to force authenticated users to send a request to a web application they are currently authenticated against.
network
low complexity
pandorafms CWE-352
7.1
2023-08-22 CVE-2023-24514 Cross-site Scripting vulnerability in Pandorafms Pandora FMS
Cross-site Scripting (XSS) vulnerability in Visual Console Module of Pandora FMS could be used to hijack admin users session cookie values, carry out phishing attacks, etc.
network
low complexity
pandorafms CWE-79
6.1
2023-08-22 CVE-2023-24515 Server-Side Request Forgery (SSRF) vulnerability in Pandorafms Pandora FMS
Server-Side Request Forgery (SSRF) vulnerability in API checker of Pandora FMS.
network
low complexity
pandorafms CWE-918
6.5
2023-08-22 CVE-2023-24516 Cross-site Scripting vulnerability in Pandorafms Pandora FMS
Cross-site Scripting (XSS) vulnerability in the Pandora FMS Special Days component allows an attacker to use it to steal the session cookie value of admin users easily with little user interaction.
network
low complexity
pandorafms CWE-79
5.4
2023-08-22 CVE-2023-24517 Unrestricted Upload of File with Dangerous Type vulnerability in Pandorafms Pandora FMS
Unrestricted Upload of File with Dangerous Type vulnerability in the Pandora FMS File Manager component, allows an attacker to make make use of this issue ( unrestricted file upload ) to execute arbitrary system commands.
network
low complexity
pandorafms CWE-434
7.2
2023-06-13 CVE-2023-2807 Authentication Bypass by Spoofing vulnerability in Pandorafms Pandora FMS
Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a password reset process for any user account without proper authentication.
network
low complexity
pandorafms CWE-290
critical
9.8
2023-02-15 CVE-2022-47373 Cross-site Scripting vulnerability in Pandorafms Pandora FMS
Reflected Cross Site Scripting in Search Functionality of Module Library in Pandora FMS Console v766 and lower.
network
low complexity
pandorafms CWE-79
6.1
2023-01-27 CVE-2022-43978 Use of Hard-coded Credentials vulnerability in Pandorafms Pandora FMS
There is an improper authentication vulnerability in Pandora FMS v764.
network
high complexity
pandorafms CWE-798
3.7
2023-01-27 CVE-2022-43979 Path Traversal vulnerability in Pandorafms Pandora FMS
There is a Path Traversal that leads to a Local File Inclusion in Pandora FMS v764.
network
low complexity
pandorafms CWE-22
critical
9.8