CVE-2023-41792: Lack of Authorization and Stored XSS Via SNMP Trap Editor Page
Published Nov 23, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allowed Javascript code to be executed in the SNMP Trap Editor. This issue affects Pandora FMS: from 700 through 773.
Affected Software
1 affected component
Artica Pandora FMS>=700<=773
Remediation
Information
Fixed in v774 and v772.2.
Event History
Nov 23, 2023
CVE Published
02:45 PM
Data Sourced
02:45 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-41792?
CVE-2023-41792 is a Cross-Site Request Forgery (CSRF) vulnerability in Pandora FMS that allows for Cross-Site Scripting (XSS) attacks.
2
How does CVE-2023-41792 affect Pandora FMS?
CVE-2023-41792 affects Pandora FMS versions 700 through 773.
3
What is the severity of CVE-2023-41792?
CVE-2023-41792 has a severity rating of medium with a CVSS score of 6.1.
4
How can CVE-2023-41792 be exploited?
CVE-2023-41792 can be exploited by performing a Cross-Site Scripting (XSS) attack through the SNMP Trap Editor page.
5
Is there a fix available for CVE-2023-41792?
Yes, users should update to a version of Pandora FMS that is not affected by this vulnerability.