First published: Sat Jun 16 2018(Updated: )
XSS in Artica Pandora FMS before 7.0 NG 723 allows an attacker to execute arbitrary code via a crafted "refr" parameter in a "/pandora_console/index.php?sec=estado&sec2=operation/agentes/estado_agente&refr=" call.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artica Pandora FMS | <7.0_ng_723 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11223 is classified as a medium severity vulnerability due to the potential for cross-site scripting (XSS) attacks.
To fix CVE-2018-11223, upgrade to Artica Pandora FMS version 7.0 NG 723 or later.
CVE-2018-11223 is a cross-site scripting (XSS) vulnerability that allows attackers to execute arbitrary code.
CVE-2018-11223 affects all versions of Artica Pandora FMS prior to 7.0 NG 723.
CVE-2018-11223 can allow attackers to manipulate the application through crafted input, potentially compromising user data.