Description
Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of event responses via a forged GET request when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Fixed v805 an v800.5
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 01 Oct 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of event responses via a forged GET request when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards. | |
| Title | CSRF in Event Response Deletion | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: PandoraFMS
Published:
Updated: 2026-10-01T09:24:43.807Z
Reserved: 2026-03-26T10:40:59.131Z
Link: CVE-2026-34189
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses