First published: Tue Aug 22 2023(Updated: )
Cross-site Scripting (XSS) vulnerability in Visual Console Module of Pandora FMS could be used to hijack admin users session cookie values, carry out phishing attacks, etc. This issue affects Pandora FMS v767 version and prior versions on all platforms.
Credit: cve-coordination@incibe.es cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
Pandorafms Pandora Fms | <=767 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-24514.
The severity of CVE-2023-24514 is medium with a CVSS score of 6.3.
Pandora FMS v767 version and prior versions are affected by CVE-2023-24514.
CVE-2023-24514 allows an attacker to hijack admin users' session cookie values and carry out phishing attacks.
Yes, an update to Pandora FMS version 767 or above will fix CVE-2023-24514.