CyberRota Analysis
AI-GeneratedThe File Manager module in Pandora FMS versions 777 and later is vulnerable to a chained CSRF and unrestricted SVG file upload flaw, which can lead to stored Cross-Site Scripting (XSS). This vulnerability allows attackers to exfiltrate session cookies and potentially take over administrator accounts. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access and data breaches.
Original NVD Description
A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 777 onwards.