First published: Tue Oct 03 2023(Updated: )
Cross-site Scripting (XSS) vulnerability in Syslog Section of Pandora FMS allows attacker to cause that users cookie value will be transferred to the attackers users server. This issue affects Pandora FMS v767 version and prior versions on all platforms.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
Artica Pandora FMS | <=767 |
Fixed in v769
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-0828 is medium with a CVSS v3.1 score of 6.1.
The Cross-site Scripting (XSS) vulnerability allows an attacker to inject malicious scripts into the Syslog Section of Pandora FMS, which can then be executed by unsuspecting users.
Pandora FMS v767 and prior versions on all platforms are affected by CVE-2023-0828.
To fix CVE-2023-0828, it is recommended to upgrade to a patched version of Pandora FMS that addresses the Cross-site Scripting (XSS) vulnerability.
More information about CVE-2023-0828 can be found at the following reference: https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/