Pandorafms

Pandora Fms

78 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.43%
  • Veröffentlicht 15.02.2023 04:15:10
  • Zuletzt bearbeitet 21.11.2024 07:29:15

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Artica PFMS Pandora FMS v765 on all allows Cross-Site Scripting (XSS). A user with edition privileges can create a Payload in the reporting dashboar...

  • EPSS 0.61%
  • Veröffentlicht 15.02.2023 04:15:10
  • Zuletzt bearbeitet 21.11.2024 07:29:15

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Artica PFMS Pandora FMS v765 on all platforms, allows Cross-Site Scripting (XSS). As a manager privilege user , create a network map containing name...

  • EPSS 0.28%
  • Veröffentlicht 27.01.2023 22:15:08
  • Zuletzt bearbeitet 21.11.2024 07:27:28

There is a stored cross-site scripting vulnerability in Pandora FMS v765 in the network maps editing functionality. An attacker could modify a network map, including on purpose the name of an XSS payload. Once created, if a user with admin privileges...

  • EPSS 0.82%
  • Veröffentlicht 27.01.2023 22:15:08
  • Zuletzt bearbeitet 21.11.2024 07:27:28

There is a Path Traversal that leads to a Local File Inclusion in Pandora FMS v764. A function is called to check that the parameter that the user has inserted does not contain malicious characteres, but this check is insufficient. An attacker could ...

  • EPSS 0.3%
  • Veröffentlicht 27.01.2023 22:15:08
  • Zuletzt bearbeitet 21.11.2024 07:27:28

There is an improper authentication vulnerability in Pandora FMS v764. The application verifies that the user has a valid session when he is not trying to do a login. Since the secret is static in generatePublicHash function, an attacker with knowled...

  • EPSS 0.38%
  • Veröffentlicht 05.08.2022 16:15:11
  • Zuletzt bearbeitet 21.11.2024 06:34:34

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the service name field.

  • EPSS 0.38%
  • Veröffentlicht 05.08.2022 16:15:11
  • Zuletzt bearbeitet 21.11.2024 06:34:34

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the event filter name field.

  • EPSS 0.38%
  • Veröffentlicht 05.08.2022 16:15:11
  • Zuletzt bearbeitet 21.11.2024 06:34:35

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via service elements.

  • EPSS 0.37%
  • Veröffentlicht 05.08.2022 16:15:11
  • Zuletzt bearbeitet 21.11.2024 06:34:35

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the module form name field.

  • EPSS 0.4%
  • Veröffentlicht 05.08.2022 16:15:10
  • Zuletzt bearbeitet 21.11.2024 06:34:34

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the transactional maps name field.