VulnerabilityModified
CVE-2014-8629
Cross-site scripting (XSS) vulnerability in the Page visualization agents in Pandora FMS 5.1 SP1 and earlier allows remote attackers to inject arbitrary web script or HTML via the refr parameter to index.php.
MEDIUM 4.3EPSS 1.89%
Does this matter?
Lower severity and a low EPSS score (1.89%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in the Page visualization agents in Pandora FMS 5.1 SP1 and earlier allows remote attackers to inject arbitrary web script or HTML via the refr parameter to index.php.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.89% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- pandorafms/pandora flexible monitoring system
- Source
- cve@mitre.org
References
- http://blog.pandorafms.org/?p=3271Patch
- http://packetstormsecurity.com/files/129112/Pandora-FMS-5.1SP1-Cross-Site-Scripting.htmlExploit
- http://seclists.org/fulldisclosure/2014/Nov/35Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98704
- http://blog.pandorafms.org/?p=3271Patch
- http://packetstormsecurity.com/files/129112/Pandora-FMS-5.1SP1-Cross-Site-Scripting.htmlExploit
- http://seclists.org/fulldisclosure/2014/Nov/35Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98704
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.