Back

HIGH

Stored Cross-Site Scripting via Directory Name in File Manager Create Directory

Published Oct 1, 2026

Description

Missing input validation and output encoding on the directory name parameter in File Manager's Create Directory allows stored XSS, executing without user interaction. Affects Pandora FMS from 777 onwards.

Affected products

Remediation

Vendor solution

Fixed v800.5 and v805

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner PandoraFMS
Published Oct 1, 2026
Updated Oct 1, 2026
Reserved Jul 21, 2026
CISA Vulnrichment
Updated Oct 1, 2026
NVD
Status Received
Modified Oct 1, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner PandoraFMS
Published Oct 1, 2026
Updated Oct 1, 2026
Exploited since n/a
EUVD-2026-90599