Vulnerabilities > Pandorafms > Pandora FMS > 771

DATE CVE VULNERABILITY TITLE RISK
2023-12-29 CVE-2023-41813 Cross-site Scripting vulnerability in Pandorafms Pandora FMS
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). Allows you to edit the Web Console user notification options. This issue affects Pandora FMS: from 700 through 774.
network
low complexity
pandorafms CWE-79
6.1
2023-12-29 CVE-2023-41814 Cross-site Scripting vulnerability in Pandorafms Pandora FMS
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS).
network
low complexity
pandorafms CWE-79
6.1
2023-12-29 CVE-2023-41815 Cross-site Scripting vulnerability in Pandorafms Pandora FMS
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). Malicious code could be executed in the File Manager section. This issue affects Pandora FMS: from 700 through 774.
network
low complexity
pandorafms CWE-79
6.1
2023-12-29 CVE-2023-44088 SQL Injection vulnerability in Pandorafms Pandora FMS
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitrary SQL queries were allowed to be executed using any account with low privileges. This issue affects Pandora FMS: from 700 through 774.
network
low complexity
pandorafms CWE-89
8.8
2023-12-29 CVE-2023-44089 Cross-site Scripting vulnerability in Pandorafms Pandora FMS
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). It was possible to execute malicious JS code on Visual Consoles. This issue affects Pandora FMS: from 700 through 774.
network
low complexity
pandorafms CWE-79
6.1