First published: Fri Jun 25 2021(Updated: )
PandoraFMS <=7.54 allows Stored XSS by placing a payload in the name field of a visual console. When a user or an administrator visits the console, the XSS payload will be executed.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artica Pandora FMS | <=754 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-35501 is a vulnerability that allows stored cross-site scripting (XSS) in PandoraFMS <=7.54 by placing a payload in the name field of a visual console.
CVE-2021-35501 is considered a medium severity vulnerability with a severity score of 5.4.
CVE-2021-35501 works by allowing an attacker to insert a malicious payload into the name field of a visual console in PandoraFMS. When a user or administrator visits the console, the XSS payload gets executed.
PandoraFMS versions up to 7.54 are affected by CVE-2021-35501.
As of now, there are no known fixes or patches for CVE-2021-35501. It is recommended to update to the latest version of PandoraFMS when a fix becomes available.