UBUNTU-CVE-2022-47373

Source
https://ubuntu.com/security/CVE-2022-47373
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-47373.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2022-47373
Upstream
  • CVE-2022-47373
Published
2023-02-15T04:15:00Z
Modified
2025-10-24T04:54:02Z
Severity
  • 6.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L CVSS Calculator
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

Reflected Cross Site Scripting in Search Functionality of Module Library in Pandora FMS Console v766 and lower. This vulnerability arises on the forget password functionality in which parameter username does not proper input validation/sanitization thus results in executing malicious JavaScript payload.

References

Affected packages

Ubuntu:16.04:LTS / pandora

Package

Name
pandora
Purl
pkg:deb/ubuntu/pandora@0.7.1-0ubuntu3?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.7.1-0ubuntu3

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "pandora",
            "binary_version": "0.7.1-0ubuntu3"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-47373.json"

Ubuntu:18.04:LTS / pandora

Package

Name
pandora
Purl
pkg:deb/ubuntu/pandora@0.7.1-0ubuntu4?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.7.1-0ubuntu3
0.7.1-0ubuntu4

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "pandora",
            "binary_version": "0.7.1-0ubuntu4"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-47373.json"