Coordinated CVEs

CVEVulnerability descriptionPublication DateSolutionAssigner CNAReported By:

CVE-2023-41812

Vulnerability of unrestricted uploading of dangerous type files in Pandora FMS allows access to functionalities not properly restricted by ACLs. This vulnerability allowed to upload PHP executable files through the file manager. This problem affects Pandora FMS: from 772 to 773.21-11-2023

This vulnerability has been fixed in Pandora FMS version 774-772.2.

Pandora FMS

External analysis

CVE-2023-41811

The Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS allows Cross-Site Scripting (XSS). This vulnerability could allow the execution of Javascript code in the news section of the web console. This problem affects Pandora FMS: from 700 to 773.21-11-2023

This vulnerability has been fixed in Pandora FMS version 774-772.2.

Pandora FMS

External analysis

CVE-2023-41810

CSRF (Cross-Site Request Forgery) vulnerability in Pandora FMS allows Cross-Site Scripting (XSS). This vulnerability could allow to execute Javascript code in the text box of some Widgets. This problem affects Pandora FMS: from 700 to 773.21-11-2023

This vulnerability has been fixed in Pandora FMS version 774-772.2.

Pandora FMS

External analysis

CVE-2023-41808

An inadequate Privilege Management vulnerability in Pandora FMS allows Privilege Escalation. This vulnerability allows an unauthorized user to escalate and read sensitive files as if he was root. This problem affects Pandora FMS: from 700 to 773.21-11-2023

This vulnerability has been fixed in Pandora FMS version 774-772.2.

Pandora FMS

External analysis

CVE-2023-41807

An inadequate privilege management vulnerability in Pandora FMS allows privilege escalation. This vulnerability allows a user to escalate permissions in the system shell. This problem affects Pandora FMS: from 700 to 773.21-11-2023

This vulnerability has been fixed in Pandora FMS version 774-772.2.

Pandora FMS

External analysis

CVE-2023-41806

An inadequate Privilege Management vulnerability in Pandora FMS allows Privilege Escalation. This vulnerability causes that a bad privilege assignment can provoke a DOS attack that affects the availability of the Pandora FMS server. This problem affects Pandora FMS: from 700 to 773.21-11-2023

This vulnerability has been fixed in Pandora FMS version 774-772.2.

Pandora FMS

External analysis

CVE-2023-41792

The Cross Site Request Forgery (CSRF) vulnerability in Pandora FMS allows Cross-Site Scripting (XSS). This vulnerability allows the execution of Javascript code in the SNMP Trap Editor. This problem affects Pandora FMS: from 700 to 773.21-11-2023

This vulnerability has been fixed in Pandora FMS version 774-772.2.

Pandora FMS

External analysis

CVE-2023-41791

Uncontrolled search path element vulnerability in Pandora FMS allows the leverage/manipulation of search paths of configuration files. This vulnerability allows access to files with sensitive information and allows to discover the password of the database administrator user. This problem affects Pandora FMS: from 700 to 772.21-11-2023

This vulnerability has been fixed in Pandora FMS version 774-772.2.

Pandora FMS

External analysis

CVE-2023-41790

Uncontrolled search path element vulnerability in Pandora FMS allows to exploit/manipulate configuration file search paths. This vulnerability allows to access the server configuration file and compromise the database. This problem affects Pandora FMS: from 700 to 774.21-11-2023

This vulnerability has been fixed in Pandora FMS version 774-772.2.

Pandora FMS

External analysis

CVE-2023-41789

The Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS allows Cross-Site Scripting (XSS). This vulnerability allows an attacker to hijack cookies and log in as that user without the need for credentials. This problem affects Pandora FMS: from 700 to 773.21-11-2023

This vulnerability has been fixed in Pandora FMS version 774-772.2.

Pandora FMS

External analysis

CVE-2023-41788

The vulnerability of unrestricted upload of dangerous files in Pandora FMS allows access to functionalities not properly restricted by ACLs. This vulnerability allows attackers to execute code through the upload of PHP files. This problem affects Pandora FMS: from 700 to 773.21-11-2023

This vulnerability has been fixed in Pandora FMS version 774-772.2.

Pandora FMS

External analysis

CVE-2023-41787

Uncontrolled search path element vulnerability in Pandora FMS allows the leverage/manipulation of search paths of configuration files. This vulnerability allows access to files with sensitive information and allows to discover the password of the database administrator user. This problem affects Pandora FMS: from 700 to 772.21-11-2023

This vulnerability has been fixed in Pandora FMS version 774-772.2.

Pandora FMS

External analysis

CVE-2023-41786

Exposing sensitive information to an unauthorised actor Pandora FMS vulnerability allows file discovery. This vulnerability allows users with low privileges to download database backups. This problem affects Pandora FMS: from 700 to 773.21-11-2023

This vulnerability has been fixed in Pandora FMS version 774-772.2.

Pandora FMS

External analysis

CVE-2023-4677

Exposing sensitive information to an unauthorised actor Pandora FMS vulnerability allows file discovery. This vulnerability allows users with low privileges to download database backups. This problem affects Pandora FMS: from 700 to 773.21-11-2023

This vulnerability has been fixed in Pandora FMS version 774-772.2.

Pandora FMS

External analysis

CVE-2023-2807Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a password reset process for any user account without proper authentication. This issue affects PandoraFMS v771 and prior versions on all platforms.13-06-2023This vulnerability has been solved in the 772 version of Pandora FMS.Ártica PFMSExternal analysis
CVE-2023-0828Cross-site Scripting (XSS) in the Syslog section of Pandora FMS that could allow an attacker to have the value of the user's cookie transferred to the attacker's server. This issue affects Pandora FMS version 767 and earlier versions on all platforms.17-04-2023This vulnerability has been solved in the 770 version of Pandora FMS.Ártica PFMSExternal analysis
CVE-2023-24518A Cross-site Request Forgery (CSRF) vulnerability in Pandora FMS allows an attacker to force authenticated users to send a request to a web application they are currently authenticated against. This issue affects Pandora FMS version 767 and earlier versions on all platforms.17-04-2023This vulnerability has been solved in the 770 version of Pandora FMS.Ártica PFMSExternal analysis
CVE-2023-24517Unrestricted Upload of File with Dangerous Type vulnerability in the Pandora FMS File Manager component, allows an attacker to make make use of this issue ( unrestricted file upload ) to execute arbitrary system commands. This issue affects Pandora FMS v767 version and prior versions on all platforms.22-02-2023This vulnerability has been solved in the 769 version of Pandora FMS.Ártica PFMSExternal analysis
CVE-2023-24516Cross-site Scripting (XSS) vulnerability in the Pandora FMS Special Days component allows an attacker to use it to steal  the session cookie value of admin users easily with little user interaction. This issue affects Pandora FMS v767 version and prior versions on all platforms.22-02-2023This vulnerability has been solved in the 769 version of Pandora FMS.Ártica PFMSExternal analysis
CVE-2023-24515Server-Side Request Forgery (SSRF) vulnerability in API checker of Pandora FMS. Application does not have a check on the URL scheme used while retrieving API URL. Rather than validating the http/https scheme, the application allows other scheme such as file, which could allow a malicious user to fetch internal file content. This issue affects Pandora FMS v767 version and prior versions on all platforms.22-02-2023This vulnerability has been solved in the 769 version of Pandora FMS.Ártica PFMSExternal analysis
CVE-2023-24514Cross-site Scripting (XSS) vulnerability in Visual Console Module of Pandora FMS could be used to hijack admin users session cookie values, carry out phishing attacks, etc. This issue affects Pandora FMS v767 version and prior versions on all platforms.22-02-2023This vulnerability has been solved in the 769 version of Pandora FMS.Ártica PFMSExternal analysis
CVE-2022-47373Reflected Cross-Site Scripting in the Search functionality of the module Library in Pandora FMS Console v766 and lower. This vulnerability arises in the forgot password functionality where the username parameter does not have proper input validation/sanitization, resulting in the execution of malicious JavaScript payload.20-12-2022This vulnerability has been solved in the 767 version of Pandora FMS.Ártica PFMSExternal analysis
CVE-2022-47372Stored Cross-Site Scripting vulnerability in the Create event section in Pandora FMS Console v766 and lower. An attacker typically exploits this vulnerability by injecting XSS payloads on popular pages of a site or passing a link to a victim, tricking them into viewing the page that contains the stored XSS payload.20-12-2022This vulnerability has been solved in the 767 version of Pandora FMS.Ártica PFMSExternal analysis
CVE-2022-45437Improper Neutralization of Input During Web Page Generation vulnerability in Artica PFMS Pandora FMS v765 on all platforms, allows Cross-Site Scripting (XSS). A user with edition privileges can create a Payload in the reporting dashboard module. An admin user can observe the Payload without interaction and attacker can get information.16-11-2022This vulnerability has been solved in the 766 version of Pandora FMS.Ártica PFMSExternal analysis
CVE-2022-45436Improper Neutralization of Input During Web Page Generation vulnerability in Artica PFMS Pandora FMS v765 on all platforms, allows Cross-Site Scripting (XSS). As a manager privilege user , create a network map containing name as xss payload. Once created, admin user must click on the edit network maps and XSS payload will be executed, which could be used for stealing admin users cookie value.16-11-2022This vulnerability has been solved in the 766 version of Pandora FMS.Ártica PFMSExternal analysis
CVE-2022-43980There is a stored cross-site scripting vulnerability in Pandora FMS v765 in the network maps editing functionality. An attacker could modify a network map, including on purpose the name of an XSS payload. Once created, if a user with admin privileges clicks on the edited network maps, the XSS payload will be executed. The exploitation of this vulnerability could allow an atacker to steal the value of the admin user´s cookie.03-11-2022This vulnerability has been solved in the 766 version of Pandora FMS.Ártica PFMSExternal analysis
CVE-2022-43979There is a Path Traversal that leads to a Local File Inclusion in Pandora FMS v764. A function is called to check that the parameter that the user has inserted does not contain malicious characteres, but this check is insufficient. An attacker could insert an absolute path to overcome the heck, thus being able to incluse any PHP file that resides on the disk. The exploitation of this vulnerability could lead to a remote code execution.03-11-2022This vulnerability has been solved in the 766 version of Pandora FMS.Ártica PFMSExternal analysis
CVE-2022-43978There is an improper authentication vulnerability in Pandora FMS v764. The application verifies that the user has a valid session when he is not trying to do a login. Since the secret is static in generatePublicHash function, an attacker with knowledge of a valid session can abuse this in order to pass the authentication check.03-11-2022This vulnerability has been solved in the 766 version of Pandora FMS.Ártica PFMSExternal analysis
CVE-2022-2059In Pandora FMS v7.0NG.761 and below, in the agent creation section, the alias parameter is vulnerable to a Stored Cross Site-Scripting. This vulnerability can be exploited by an attacker with administrator privileges logged in the system.14-06-2022This vulnerability has been solved in the 762 version of Pandora FMS.Ártica PFMSExternal analysis
CVE-2022-2032In Pandora FMS v7.0NG.761 and below, in the file manager section, the dirname parameter is vulnerable to a Stored Cross Site-Scripting. This vulnerability can be exploited by an attacker with administrator privileges logged in the system.14-06-2022This vulnerability has been solved in the 762 version of Pandora FMS.Ártica PFMSExternal analysis
CVE-2022-1648Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intended images directory which is restricted to execute the .php file. The impact could lead to a Remote Code Execution with running application privilege.13-05-2022This vulnerability has been solved in the 761 version of Pandora FMS.Ártica PFMSExternal analysis
CVE-2022-26310Pandora FMS v7.0NG.760 and below allows an improper authorization in User Management where any authenticated user with access to the User Management module could create, modify or delete any user with full admin privilege. The impact could lead to a vertical privilege escalation to access the privileges of a higher-level user or typically an admin user.13-05-2022This vulnerability has been solved in the 761 version of Pandora FMS.Ártica PFMSExternal analysis
CVE-2022-26309Pandora FMS v7.0NG.760 and below allows a Cross-Site Request Forgery in Bulk operation (User operation) resulting in an elevation of privilege to Administrator group.13-05-2022This vulnerability has been solved in the 761 version of Pandora FMS.Ártica PFMSExternal analysis
CVE-2022-26308Pandora FMS v7.0NG.760 and below allows an improper access control in Configuration (Credential store) where a user with the role of Operator (Write) could create, delete, view existing keys which are outside the intended role.13-05-2022This vulnerability has been solved in the 761 version of Pandora FMS.Ártica PFMSExternal analysis
CVE-2021-46681There is an XSS vulnerability in Pandora FMS version 756 and below, which allows an attacker to execute javascript code through the massive operation name field.21-02-2022This vulnerability has been solved in the 757 version of Pandora FMS.Ártica PFMSInternal analysis
CVE-2021-46680There is an XSS vulnerability in Pandora FMS version 756 and below, which allows an attacker to execute javascript code through the module form name field.21-02-2022This vulnerability has been solved in the 757 version of Pandora FMS.Ártica PFMSInternal analysis
CVE-2021-46679There is an XSS vulnerability in Pandora FMS version 756 and below, which allows an attacker to execute javascript code through service elements.21-02-2022This vulnerability has been solved in the 757 version of Pandora FMS.Ártica PFMSInternal analysis
CVE-2021-46678There is an XSS vulnerability in Pandora FMS version 756 and below, which allows an attacker to execute javascript code through the service name field.21-02-2022This vulnerability has been solved in the 757 version of Pandora FMS.Ártica PFMSInternal analysis
CVE-2021-46677There is an XSS vulnerability in Pandora FMS version 756 and below, which allows an attacker to execute javascript code through the event filter name field.21-02-2022This vulnerability has been solved in the 757 version of Pandora FMS.Ártica PFMSInternal analysis
CVE-2021-46676There is an XSS vulnerability in Pandora FMS version 756 and below, which allows an attacker to execute javascript code through the transactional maps name field.21-02-2022This vulnerability has been solved in the 757 version of Pandora FMS.Ártica PFMSInternal analysis
CVE-2022-0507Found a potential security vulnerability inside the Pandora API. Affected Pandora FMS version range: all versions of NG version, up to OUM 759. This vulnerability could allow an attacker with authenticated IP to inject SQL.10-02-2022This vulnerability has been solved in the 760 version of Pandora FMS.Ártica PFMS-