CVE-2022-26309: Cross-Site Request en Bulk operation (User operation)
Pandora FMS v7.0NG.759 allows Cross-Site Request Forgery in Bulk operation (User operation) resulting in elevation of privilege to Administrator group.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-26309?
CVE-2022-26309 is a vulnerability in Pandora FMS v7.0NG.759 that allows Cross-Site Request Forgery in Bulk operation, resulting in elevation of privilege to the Administrator group.
What is the severity of CVE-2022-26309?
CVE-2022-26309 has a severity rating of 8.8 (high).
How does CVE-2022-26309 affect Pandora FMS?
CVE-2022-26309 affects Pandora FMS v7.0NG.759 by enabling Cross-Site Request Forgery, which can lead to privilege elevation to the Administrator group.
What is the Common Weakness Enumeration (CWE) for CVE-2022-26309?
The CWE for CVE-2022-26309 is CWE-352 (Cross-Site Request Forgery).
Where can I find more information about CVE-2022-26309?
You can find more information about CVE-2022-26309 at the following references: [https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/](https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/) and [https://www.incibe.es/en/cve-assignment-publication/coordinated-cves](https://www.incibe.es/en/cve-assignment-publication/coordinated-cves).