Show filters
47 Total Results
Displaying 1-10 of 47
Sort by:
Attacker Value
Very High
CVE-2024-11320
Disclosure Date: November 21, 2024 (last updated December 21, 2024)
Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <=777.4
1
Attacker Value
Moderate
CVE-2021-35501
Disclosure Date: June 25, 2021 (last updated November 28, 2024)
PandoraFMS <=7.54 allows Stored XSS by placing a payload in the name field of a visual console. When a user or an administrator visits the console, the XSS payload will be executed.
1
Attacker Value
Unknown
CVE-2024-9987
Disclosure Date: October 22, 2024 (last updated October 26, 2024)
A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv functionality. This issue affects Pandora FMS: from 700 through <777.3.
0
Attacker Value
Unknown
CVE-2024-35308
Disclosure Date: October 22, 2024 (last updated October 26, 2024)
A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. This issue affects Pandora FMS: from 700 through <777.3.
0
Attacker Value
Unknown
CVE-2023-44089
Disclosure Date: December 29, 2023 (last updated January 05, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). It was possible to execute malicious JS code on Visual Consoles. This issue affects Pandora FMS: from 700 through 774.
0
Attacker Value
Unknown
CVE-2023-44088
Disclosure Date: December 29, 2023 (last updated January 05, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitrary SQL queries were allowed to be executed using any account with low privileges. This issue affects Pandora FMS: from 700 through 774.
0
Attacker Value
Unknown
CVE-2023-41815
Disclosure Date: December 29, 2023 (last updated January 05, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). Malicious code could be executed in the File Manager section. This issue affects Pandora FMS: from 700 through 774.
0
Attacker Value
Unknown
CVE-2023-41814
Disclosure Date: December 29, 2023 (last updated January 05, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). Through an HTML payload (iframe tag) it is possible to carry out XSS attacks when the user receiving the messages opens their notifications. This issue affects Pandora FMS: from 700 through 774.
0
Attacker Value
Unknown
CVE-2023-41813
Disclosure Date: December 29, 2023 (last updated January 05, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). Allows you to edit the Web Console user notification options. This issue affects Pandora FMS: from 700 through 774.
0
Attacker Value
Unknown
CVE-2023-24518
Disclosure Date: October 03, 2023 (last updated October 09, 2023)
A Cross-site Request Forgery (CSRF) vulnerability in Pandora FMS allows an attacker to force authenticated users to send a request to a web application they are currently authenticated against. This issue affects Pandora FMS version 767 and earlier versions on all platforms.
0