Loading HuntDB...

GHSA-vwrj-5xvr-9v9x

GitHub Security Advisory

⚠ Unreviewed LOW Has CVE

Advisory Details

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). Through an HTML payload (iframe tag) it is possible to carry out XSS attacks when the user receiving the messages opens their notifications. This issue affects Pandora FMS: from 700 through 774.

Related CVEs

Key Information

GHSA ID
GHSA-vwrj-5xvr-9v9x
Published
December 29, 2023 12:30 PM
Last Modified
January 5, 2024 6:30 AM
CVSS Score
2.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 14, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.