First published: Wed Feb 15 2023(Updated: )
Stored cross-site scripting vulnerability in the Create event section in Pandora FMS Console v766 and lower. An attacker typically exploits this vulnerability by injecting XSS payloads on popular pages of a site or passing a link to a victim, tricking them into viewing the page that contains the stored XSS payload.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
Artica Pandora FMS | <=766 |
fixed in v767
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-47372 is high.
CVE-2022-47372 affects Pandora FMS Console v766 and lower.
An attacker can exploit CVE-2022-47372 by injecting XSS payloads on popular pages or tricking victims into viewing a page containing the vulnerability.
Please refer to the official references for information on available fixes for CVE-2022-47372.
CVE-2022-47372 is associated with CWE-79 and CWE-352.