CVE-2023-41810: Stored XSS Via Dashboard Panel
Published Nov 23, 2023
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allowed Javascript code to be executed in some Widgets' text box. This issue affects Pandora FMS: from 700 through 773.
Affected Software
1 affected component
Artica Pandora FMS>=700<=773
Remediation
Information
Fixed in v774 and v772.2.
Event History
Nov 23, 2023
CVE Published
02:52 PM
Data Sourced
02:52 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-41810?
The severity of CVE-2023-41810 is medium with a CVSS score of 6.1.
2
How does CVE-2023-41810 affect Pandora FMS?
CVE-2023-41810 affects Pandora FMS versions 700 through 773.
3
What is the vulnerability type of CVE-2023-41810?
CVE-2023-41810 is a Stored XSS vulnerability.
4
How can an attacker exploit CVE-2023-41810?
An attacker can exploit CVE-2023-41810 by injecting malicious JavaScript code into some Widgets' text boxes.
5
Is there a fix available for CVE-2023-41810?
Yes, there is a fix available for CVE-2023-41810. It is recommended to update Pandora FMS to a version beyond 773 to address this vulnerability.