First published: Tue Aug 22 2023(Updated: )
Cross-site Scripting (XSS) vulnerability in the Pandora FMS Special Days component allows an attacker to use it to steal the session cookie value of admin users easily with little user interaction. This issue affects Pandora FMS v767 version and prior versions on all platforms.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
Artica Pandora FMS | <=767 |
Fixed in v769
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-24516 is medium with a rating of 5.9.
The Cross-site Scripting vulnerability in the Pandora FMS Special Days component allows an attacker to steal the session cookie value of admin users with minimal user interaction.
Pandora FMS v767 and prior versions on all platforms are affected by CVE-2023-24516.
To fix the Cross-site Scripting vulnerability, you should update Pandora FMS to a version that is not affected, if available, or apply any patches or security updates provided by Pandora FMS.
You can find more information about CVE-2023-24516 on the Pandora FMS website at https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/.