Stored XSS Vulnerability in File Manager of Pandora FMS
CVE-2026-64950
8.4HIGH
What is CVE-2026-64950?
A security flaw in the File Manager component of Pandora FMS allows for stored Cross-Site Scripting (XSS) due to inadequate input validation and output encoding on the directory name parameter. This vulnerability enables attackers to execute malicious scripts without any user interaction, posing a significant risk for users of impacted versions starting from 777. Immediate mitigation steps should be taken to protect against potential exploits.
Affected Version(s)
Pandora FMS all 777
