Vulnerabilities > Pandorafms > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-12-29 | CVE-2023-41813 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). Allows you to edit the Web Console user notification options. This issue affects Pandora FMS: from 700 through 774. | 6.1 |
2023-12-29 | CVE-2023-41814 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). | 6.1 |
2023-12-29 | CVE-2023-41815 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). Malicious code could be executed in the File Manager section. This issue affects Pandora FMS: from 700 through 774. | 6.1 |
2023-12-29 | CVE-2023-44089 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). It was possible to execute malicious JS code on Visual Consoles. This issue affects Pandora FMS: from 700 through 774. | 6.1 |
2023-10-03 | CVE-2023-0828 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS Cross-site Scripting (XSS) vulnerability in Syslog Section of Pandora FMS allows attacker to cause that users cookie value will be transferred to the attackers users server. | 6.1 |
2023-08-22 | CVE-2023-24514 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS Cross-site Scripting (XSS) vulnerability in Visual Console Module of Pandora FMS could be used to hijack admin users session cookie values, carry out phishing attacks, etc. | 6.1 |
2023-08-22 | CVE-2023-24515 | Server-Side Request Forgery (SSRF) vulnerability in Pandorafms Pandora FMS Server-Side Request Forgery (SSRF) vulnerability in API checker of Pandora FMS. | 6.5 |
2023-08-22 | CVE-2023-24516 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS Cross-site Scripting (XSS) vulnerability in the Pandora FMS Special Days component allows an attacker to use it to steal the session cookie value of admin users easily with little user interaction. | 5.4 |
2023-02-15 | CVE-2022-45436 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS 765 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Artica PFMS Pandora FMS v765 on all platforms, allows Cross-Site Scripting (XSS). | 4.8 |
2023-02-15 | CVE-2022-45437 | Cross-site Scripting vulnerability in Pandorafms Pandora FMS 765 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Artica PFMS Pandora FMS v765 on all allows Cross-Site Scripting (XSS). | 4.8 |