CVE-2021-46680: Vulnerability XSS in module form name field
Published Aug 5, 2022
·Updated
A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the module form name field.
Affected Software
1 affected component
PandoraFMS Pandora FMS<=756
Remediation
Information
This vulnerability has been solved in the 757 version of Pandora FMS.
Event History
Aug 5, 2022
CVE Published
via MITRE·03:26 PM
Data Sourced
via MITRE·03:26 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-46680?
The severity of CVE-2021-46680 is medium.
2
How does CVE-2021-46680 affect Pandora FMS?
CVE-2021-46680 affects Pandora FMS version 756 and below.
3
What is the vulnerability type of CVE-2021-46680?
CVE-2021-46680 is a XSS (Cross-Site Scripting) vulnerability.
4
What is the CWE ID of CVE-2021-46680?
The CWE ID of CVE-2021-46680 is 79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).
5
How can I fix CVE-2021-46680 in Pandora FMS?
To fix CVE-2021-46680 in Pandora FMS, you should update to a version higher than 756.