Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Fixed v800.5 and v805
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pandora Fms
Pandora Fms pandora Fms |
|
| Vendors & Products |
Pandora Fms
Pandora Fms pandora Fms |
Thu, 01 Oct 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing input validation and output encoding on the directory name parameter in File Manager's Create Directory allows stored XSS, executing without user interaction. Affects Pandora FMS from 777 onwards. | |
| Title | Stored Cross-Site Scripting via Directory Name in File Manager Create Directory | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: PandoraFMS
Published:
Updated: 2026-10-01T09:30:09.661Z
Reserved: 2026-07-21T06:52:17.077Z
Link: CVE-2026-64950
No data.
Status : Received
Published: 2026-10-01T10:17:16.367
Modified: 2026-10-01T10:17:16.367
Link: CVE-2026-64950
No data.
OpenCVE Enrichment
Updated: 2026-10-01T10:45:07Z
