CVE-2022-2032: Stored Cross Site-Scripting in File Manager
In Pandora FMS v7.0NG.761 and below, in the file manager section, the dirname parameter is vulnerable to a Stored Cross Site-Scripting. This vulnerability can be exploited by an attacker with administrator privileges logged in the system.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this Pandora FMS issue?
The vulnerability ID for this Pandora FMS issue is CVE-2022-2032.
What is the severity of CVE-2022-2032?
The severity of CVE-2022-2032 is medium with a severity value of 4.8.
What is the affected software version for CVE-2022-2032?
The affected software version for CVE-2022-2032 is Pandora FMS v7.0NG.761 and below.
How can an attacker exploit CVE-2022-2032?
An attacker with administrator privileges logged in the system can exploit CVE-2022-2032 by exploiting the vulnerable dirname parameter in the file manager section, allowing for Stored Cross-Site Scripting (XSS) attacks.
Are there any references for CVE-2022-2032?
Yes, there are references for CVE-2022-2032. You can find them at: - https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/ - https://www.incibe.es/en/cve-assignment-publication/coordinated-cves