Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-24516


Cross-site Scripting (XSS) vulnerability in the Pandora FMS Special Days component allows an attacker to use it to steal the session cookie value of admin users easily with little user interaction. This issue affects Pandora FMS v767 version and prior versions on all platforms.


Published

2023-08-22T19:16:34.557

Last Modified

2024-11-21T07:48:02.007

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-79
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application pandorafms pandora_fms ≤ 767 Yes

References