Description
A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 777 onwards.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Fixed v800.5 and v805
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 01 Oct 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 777 onwards. | |
| Title | CSRF Bypass Leading to Stored Cross-Site Scripting via Unrestricted SVG Upload in File Manager | |
| Weaknesses | CWE-352 CWE-79 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: PandoraFMS
Published:
Updated: 2026-10-01T09:26:53.042Z
Reserved: 2026-07-21T06:52:17.076Z
Link: CVE-2026-64946
No data.
No data.
No data.
OpenCVE Enrichment
No data.