CVE-2023-24516

Published Aug 22, 2023

Last updated a year ago

Overview

Description
Cross-site Scripting (XSS) vulnerability in the Pandora FMS Special Days component allows an attacker to use it to steal the session cookie value of admin users easily with little user interaction. This issue affects Pandora FMS v767 version and prior versions on all platforms.
Source
cve-coordination@incibe.es
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
5.4
Impact score
2.7
Exploitability score
2.3
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Severity
MEDIUM

Weaknesses

cve-coordination@incibe.es
CWE-79
nvd@nist.gov
CWE-79

Social media

Hype score
Not currently trending

Configurations