CVE-2022-47372: Stored cross-site scripting vulnerability in create event section
Published Feb 15, 2023
·Updated
Stored cross-site scripting vulnerability in the Create event section in Pandora FMS Console v766 and lower. An attacker typically exploits this vulnerability by injecting XSS payloads on popular pages of a site or passing a link to a victim, tricking them into viewing the page that contains the stored XSS payload.
Affected Software
1 affected component
PandoraFMS Pandora FMS<=766
Remediation
Information
fixed in v767
Event History
Feb 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-47372?
The severity of CVE-2022-47372 is high.
2
How does CVE-2022-47372 affect Pandora FMS Console?
CVE-2022-47372 affects Pandora FMS Console v766 and lower.
3
How can an attacker exploit CVE-2022-47372?
An attacker can exploit CVE-2022-47372 by injecting XSS payloads on popular pages or tricking victims into viewing a page containing the vulnerability.
4
Is there a fix available for CVE-2022-47372?
Please refer to the official references for information on available fixes for CVE-2022-47372.
5
What are the Common Weakness Enumeration (CWE) IDs associated with CVE-2022-47372?
CVE-2022-47372 is associated with CWE-79 and CWE-352.