Cross-site Scripting (XSS) vulnerability in the Pandora FMS Special Days component allows an attacker to use it to steal the session cookie value of admin users easily with little user interaction. This issue affects Pandora FMS v767 version and prior versions on all platforms.
References
Link | Resource |
---|---|
https://gist.github.com/Argonx21/5ef4d123c975285b3a42835c8e81603a | Exploit Third Party Advisory |
https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/ | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: INCIBE
Published: 2023-08-22T13:03:39.181Z
Updated: 2023-10-16T09:48:30.086Z
Reserved: 2023-01-25T13:49:34.265Z
Link: CVE-2023-24516
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-08-22T19:16:34.557
Modified: 2023-11-02T01:21:22.490
Link: CVE-2023-24516
JSON object: View
Redhat Information
No data.
CWE