CVE-2023-24516: Stored Cross Site Scripting - Special Days Module
Cross-site Scripting (XSS) vulnerability in the Pandora FMS Special Days component allows an attacker to use it to steal the session cookie value of admin users easily with little user interaction. This issue affects Pandora FMS v767 version and prior versions on all platforms.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24516?
The severity of CVE-2023-24516 is medium with a rating of 5.9.
How does the Cross-site Scripting vulnerability in Pandora FMS Special Days component work?
The Cross-site Scripting vulnerability in the Pandora FMS Special Days component allows an attacker to steal the session cookie value of admin users with minimal user interaction.
Which version of Pandora FMS is affected by CVE-2023-24516?
Pandora FMS v767 and prior versions on all platforms are affected by CVE-2023-24516.
How can I fix the Cross-site Scripting vulnerability in Pandora FMS Special Days component?
To fix the Cross-site Scripting vulnerability, you should update Pandora FMS to a version that is not affected, if available, or apply any patches or security updates provided by Pandora FMS.
Where can I find more information about CVE-2023-24516?
You can find more information about CVE-2023-24516 on the Pandora FMS website at https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/.