VulnerabilityModified
CVE-2020-11749
Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views.
CRITICAL 9.0EPSS 16.2%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can trigger a Cross Site Scripting (XSS), which can run arbitrary code to allow Remote Code Execution as root or apache2.
- CVSS 3.1
- 9.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
- EPSS
- 16.23% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- pandorafms/pandora fms
- Source
- cve@mitre.org
References
- https://medium.com/%40tehwinsam/multiple-xss-on-pandorafms-7-0-ng-744-64b244b8523c
- https://packetstormsecurity.com/files/158389/Pandora-FMS-7.0-NG-746-Script-Insertion-Code-Execution.htmlPoCExploit, Third Party Advisory, VDB Entry
- https://pandorafms.com/downloads/whats-new-747-EN.pdfRelease Notes, Vendor Advisory
- https://www.exploit-db.com/exploits/48707Exploit, Third Party Advisory, VDB Entry
- https://medium.com/%40tehwinsam/multiple-xss-on-pandorafms-7-0-ng-744-64b244b8523c
- https://packetstormsecurity.com/files/158389/Pandora-FMS-7.0-NG-746-Script-Insertion-Code-Execution.htmlPoCExploit, Third Party Advisory, VDB Entry
- https://pandorafms.com/downloads/whats-new-747-EN.pdfRelease Notes, Vendor Advisory
- https://www.exploit-db.com/exploits/48707Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.