CVE-2022-45437
Stored cross-site scripting vulnerability in the reporting dashboard module
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Artica PFMS Pandora FMS v765 on all allows Cross-Site Scripting (XSS). A user with edition privileges can create a Payload in the reporting dashboard module. An admin user can observe the Payload without interaction and attacker can get information.
Vulnerabilidad de neutralización inadecuada de la entrada durante la generación de la página web en Artica PFMS Pandora FMS v765 en todas las plataformas, permite Cross-Site Scripting (XSS). Un usuario con privilegios de edición puede crear un Payload en el módulo del panel de informes. Un usuario administrador puede observar el Payload sin interacción y el atacante puede obtener información.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-11-15 CVE Reserved
- 2023-02-15 CVE Published
- 2024-08-03 CVE Updated
- 2024-09-07 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://gist.github.com/damodarnaik/06180e8a5aa237b38740486b3e398011 | Related |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://pandorafms.com/en/security/common-vulnerabilities-and-exposures | 2023-10-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pandorafms Search vendor "Pandorafms" | Pandora Fms Search vendor "Pandorafms" for product "Pandora Fms" | 765 Search vendor "Pandorafms" for product "Pandora Fms" and version "765" | - |
Affected
|