First published: Tue Feb 04 2020(Updated: )
PandoraFMS 742 suffers from multiple XSS vulnerabilities, affecting the Agent Management, Report Builder, and Graph Builder components. An authenticated user can inject dangerous content into a data store that is later read and included in dynamic content.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artica Pandora FMS | =742 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19968 is a vulnerability found in PandoraFMS version 742 that allows authenticated users to inject dangerous content into a data store.
CVE-2019-19968 affects the Agent Management, Report Builder, and Graph Builder components of PandoraFMS.
An authenticated user can exploit CVE-2019-19968 by injecting dangerous content into a data store, which is later included in dynamic content.
CVE-2019-19968 has a severity rating of 5.4, which is considered medium.
To mitigate CVE-2019-19968, it is recommended to upgrade to a patched version of PandoraFMS that addresses the XSS vulnerabilities.