Reflected Cross Site Scripting in Search Functionality of Module Library in Pandora FMS Console v766 and lower. This vulnerability arises on the forget password functionality in which parameter username does not proper input validation/sanitization thus results in executing malicious JavaScript payload.
References
Link | Resource |
---|---|
https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/ | Vendor Advisory |
https://github.com/Argonx21/CVE-2022-47373 | Third Party Advisory |
Configurations
Information
Published : 2023-02-14 20:15
Updated : 2023-02-23 11:30
NVD link : CVE-2022-47373
Mitre link : CVE-2022-47373
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
pandorafms
- pandora_fms