CVE-2023-41811: Stored XSS Via Site News Page
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allowed Javascript code to be executed in the news section of the web console. This issue affects Pandora FMS: from 700 through 773.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-41811?
CVE-2023-41811 is a vulnerability in Pandora FMS that allows for stored cross-site scripting (XSS) attacks via the site news page.
What is the severity of CVE-2023-41811?
CVE-2023-41811 has a severity rating of medium.
How does CVE-2023-41811 affect Pandora FMS?
CVE-2023-41811 affects Pandora FMS versions 700 through 773.
What is cross-site scripting (XSS)?
Cross-site scripting (XSS) is a type of vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
How can I fix CVE-2023-41811 in Pandora FMS?
To fix CVE-2023-41811 in Pandora FMS, you should update to the latest version available and ensure that all input in the news section of the web console is properly validated and sanitized to prevent XSS attacks.