First published: Tue Oct 03 2023(Updated: )
A Cross-site Request Forgery (CSRF) vulnerability in Pandora FMS allows an attacker to force authenticated users to send a request to a web application they are currently authenticated against. This issue affects Pandora FMS version 767 and earlier versions on all platforms.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
Artica Pandora FMS | <=767 |
Fixed in v769
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-24518 is high with a CVSS score of 7.1.
The CSRF vulnerability in Pandora FMS allows an attacker to trick authenticated users into performing unwanted actions on their behalf.
The CSRF vulnerability in Pandora FMS affects version 767 and earlier versions on all platforms.
Yes, it is recommended to update to a version higher than 767 to mitigate the CSRF vulnerability in Pandora FMS.
You can find more information about CVE-2023-24518 on the Pandora FMS website.