CVE-2018-11223: XSS
Published Jun 15, 2018
·Updated
XSS in Artica Pandora FMS before 7.0 NG 723 allows an attacker to execute arbitrary code via a crafted "refr" parameter in a "/pandoraconsole/index.php?sec=estado&sec2=operation/agentes/estadoagente&refr=" call.
Affected Software
1 affected component
PandoraFMS Artica Pandora Fms<7.0_ng_723
Event History
Jun 15, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-11223?
CVE-2018-11223 is classified as a medium severity vulnerability due to the potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2018-11223?
To fix CVE-2018-11223, upgrade to Artica Pandora FMS version 7.0 NG 723 or later.
3
What type of vulnerability is CVE-2018-11223?
CVE-2018-11223 is a cross-site scripting (XSS) vulnerability that allows attackers to execute arbitrary code.
4
Which software versions are affected by CVE-2018-11223?
CVE-2018-11223 affects all versions of Artica Pandora FMS prior to 7.0 NG 723.
5
How does CVE-2018-11223 impact users?
CVE-2018-11223 can allow attackers to manipulate the application through crafted input, potentially compromising user data.