Vulnerabilities > Pandorafms > Pandora FMS > 767

DATE CVE VULNERABILITY TITLE RISK
2023-08-22 CVE-2023-24516 Unspecified vulnerability in Pandorafms Pandora FMS
Cross-site Scripting (XSS) vulnerability in the Pandora FMS Special Days component allows an attacker to use it to steal the session cookie value of admin users easily with little user interaction.
network
low complexity
pandorafms
5.4
2023-08-22 CVE-2023-24517 Unspecified vulnerability in Pandorafms Pandora FMS
Unrestricted Upload of File with Dangerous Type vulnerability in the Pandora FMS File Manager component, allows an attacker to make make use of this issue ( unrestricted file upload ) to execute arbitrary system commands.
network
low complexity
pandorafms
7.2
2023-06-13 CVE-2023-2807 Authentication Bypass by Spoofing vulnerability in Pandorafms Pandora FMS
Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a password reset process for any user account without proper authentication.
network
low complexity
pandorafms CWE-290
critical
9.8