CVE-2020-11749
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 16%
exploitation probability
16%top 3% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can trigger a Cross Site Scripting (XSS), which can run arbitrary code to allow Remote Code Execution as root or apache2.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencepacketstormsecurity.com/files/158389/Pandora-FMS-7.0-NG-746-Script-Insertion-Code-Execution.htmlPoCunverifiedcve_referencewww.exploit-db.com/exploits/48707unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.