Lucene search

K
cveINCIBECVE-2023-0828
HistoryOct 03, 2023 - 11:15 a.m.

CVE-2023-0828

2023-10-0311:15:25
CWE-79
INCIBE
web.nvd.nist.gov
33
cve-2023-0828
cross-site scripting
xss
pandora fms
syslog section
nvd
security vulnerability

CVSS3

6.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L

EPSS

0.001

Percentile

20.2%

Cross-site Scripting (XSS) vulnerability in Syslog Section of Pandora FMS allows attacker to cause that users cookie value will be transferred to the attackers users server. This issue affects Pandora FMS v767 version and prior versions on all platforms.

Affected configurations

Nvd
Vulners
Vulnrichment
Node
pandorafmspandora_fmsRange767
VendorProductVersionCPE
pandorafmspandora_fms*cpe:2.3:a:pandorafms:pandora_fms:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "All"
    ],
    "product": "Pandora FMS",
    "vendor": "Artica PFMS",
    "versions": [
      {
        "lessThanOrEqual": "v767",
        "status": "affected",
        "version": "v0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

6.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L

EPSS

0.001

Percentile

20.2%

Related for CVE-2023-0828