CVE-2017-15936: XSS
Published Oct 27, 2017
·Updated
In Artica Pandora FMS version 7.0, an Attacker with write Permission can create an agent with an XSS Payload; when a user enters the agent definitions page, the script will get executed.
Affected Software
1 affected component
Artica Pandora FMS=7.0
Event History
Oct 27, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15936?
CVE-2017-15936 has a high severity rating due to the potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2017-15936?
To fix CVE-2017-15936, update Artica Pandora FMS to a version released after 7.0 that addresses this vulnerability.
3
Who is affected by CVE-2017-15936?
Users of Artica Pandora FMS version 7.0 are affected by CVE-2017-15936 if they have write permissions.
4
What type of vulnerability is CVE-2017-15936?
CVE-2017-15936 is a cross-site scripting (XSS) vulnerability.
5
What are the consequences of exploiting CVE-2017-15936?
Exploiting CVE-2017-15936 allows attackers to execute arbitrary scripts in the context of a user's browser.