First published: Wed Feb 15 2023(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Artica PFMS Pandora FMS v765 on all allows Cross-Site Scripting (XSS). A user with edition privileges can create a Payload in the reporting dashboard module. An admin user can observe the Payload without interaction and attacker can get information.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
Artica Pandora FMS | =765 |
fixed in v766
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45437 is a vulnerability known as 'Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)', which affects Artica PFMS Pandora FMS v765.
CVE-2022-45437 has a severity rating of 4.8 (Medium).
CVE-2022-45437 allows for Cross-Site Scripting (XSS) attacks in Artica PFMS Pandora FMS v765, where a user with edition privileges can create a payload in the reporting dashboard module.
An admin user in Artica PFMS Pandora FMS v765 can observe the payload created by a user with edition privileges.
The CWE for CVE-2022-45437 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation (Cross-site Scripting).