ZeroHour

CVE-2023-24516

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p38
Published
()
Modified
Description

Cross-site Scripting (XSS) vulnerability in the Pandora FMS Special Days component allows an attacker to use it to steal the session cookie value of admin users easily with little user interaction. This issue affects Pandora FMS v767 version and prior versions on all platforms.

Vendors
pandorafms
Products
pandora fms
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.