CVE-2022-47373

MEDIUM

Pandora FMS Console <v766 - XSS

Title source: llm
STIX 2.1

Description

Reflected Cross Site Scripting in Search Functionality of Module Library in Pandora FMS Console v766 and lower. This vulnerability arises on the forget password functionality in which parameter username does not proper input validation/sanitization thus results in executing malicious JavaScript payload.

Exploits (1)

nomisec WRITEUP
by Argonx21 · poc
https://github.com/Argonx21/CVE-2022-47373

References (2)

Core 2

Scores

CVSS v3 6.4
EPSS 0.0066
EPSS Percentile 71.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-352 CWE-79
Status published
Products (1)
pandorafms/pandora_fms < 766
Published Feb 15, 2023
Tracked Since Feb 18, 2026