Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c9jf-g47r-97q7

Опубликовано: 06 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

There is a stored cross-site scripting vulnerability in Pandora FMS v765 in the network maps editing functionality. An attacker could modify a network map, including on purpose the name of an XSS payload. Once created, if a user with admin privileges clicks on the edited network maps, the XSS payload will be executed. The exploitation of this vulnerability could allow an atacker to steal the value of the admin user´s cookie.

There is a stored cross-site scripting vulnerability in Pandora FMS v765 in the network maps editing functionality. An attacker could modify a network map, including on purpose the name of an XSS payload. Once created, if a user with admin privileges clicks on the edited network maps, the XSS payload will be executed. The exploitation of this vulnerability could allow an atacker to steal the value of the admin user´s cookie.

EPSS

Процентиль: 40%
0.00179
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-352
CWE-79

Связанные уязвимости

CVSS3: 5.2
nvd
больше 2 лет назад

There is a stored cross-site scripting vulnerability in Pandora FMS v765 in the network maps editing functionality. An attacker could modify a network map, including on purpose the name of an XSS payload. Once created, if a user with admin privileges clicks on the edited network maps, the XSS payload will be executed. The exploitation of this vulnerability could allow an atacker to steal the value of the admin user´s cookie.

CVSS3: 3.7
fstec
почти 3 года назад

Уязвимость сервера приложений Apache Tomcat, связанная с ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 40%
0.00179
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-352
CWE-79