CVE-2021-35501: XSS
PandoraFMS <=7.54 allows Stored XSS by placing a payload in the name field of a visual console. When a user or an administrator visits the console, the XSS payload will be executed.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-35501?
CVE-2021-35501 is a vulnerability that allows stored cross-site scripting (XSS) in PandoraFMS <=7.54 by placing a payload in the name field of a visual console.
How severe is CVE-2021-35501?
CVE-2021-35501 is considered a medium severity vulnerability with a severity score of 5.4.
How does CVE-2021-35501 work?
CVE-2021-35501 works by allowing an attacker to insert a malicious payload into the name field of a visual console in PandoraFMS. When a user or administrator visits the console, the XSS payload gets executed.
What software versions are affected by CVE-2021-35501?
PandoraFMS versions up to 7.54 are affected by CVE-2021-35501.
Are there any known fixes or patches for CVE-2021-35501?
As of now, there are no known fixes or patches for CVE-2021-35501. It is recommended to update to the latest version of PandoraFMS when a fix becomes available.