CVE-2022-47373
Summary
| CVE | CVE-2022-47373 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-15 04:15:00 UTC |
| Updated | 2023-02-23 19:30:00 UTC |
| Description | Reflected Cross Site Scripting in Search Functionality of Module Library in Pandora FMS Console v766 and lower. This vulnerability arises on the forget password functionality in which parameter username does not proper input validation/sanitization thus results in executing malicious JavaScript payload. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pandorafms | Pandora Fms | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| pandorafms.com/en/security/common-vulnerabilities-and-exposures | CONFIRM | pandorafms.com | |
| GitHub - Argonx21/CVE-2022-47373: Reflected Cross Site Scripting Vulnerability in PandoraFMS <= v766 | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.