
pandorafms <= Package v765 RRR における、セッションハイジャックにつながる反射型クロスサイトスクリプティング。
"http://localhost:8080/pandora_console/index.php?sec=network&sec2=operation/agentes/pandora_networkmap" のヘルプボタンを押してリクエストを取得します(POCに示されているとおり)。 Add the payload in the "b" parameter in the request. Copy the URL with payload in it, and it to the user logged in as admin. When Admin user try to visit the malicious link payload will gets executed. XSSペイロードが実行され、管理者ユーザーのCookie値を盗むなどに使用される可能性があります。