Showing 4 vulnerabilities on this page for pandora_fms

Signals CISA KEV Ransomware Nuclei
artica vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Unauth Time-Based SQL Injection via API

Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora FMS: from 700 through <777.

CWE-89Jun 10, 2024
CVSS8.9v4.0EPSS0.374%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

OS Command Injection

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Pandora FMS on all allows OS Command Injection. This vulnerability allowed to create a reverse shell and execute commands in the OS. This issue affects Pandora FMS: from 700 through <776.

CWE-78Mar 19, 2024
CVSS7.6v3.1EPSS0.846%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

artica pandora_fms Missing Authentication for Critical Function

In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format and it contains user names, user IDs, private messages, and timestamps.

CWE-200CWE-306Mar 23, 20201 related artifact
CVSS5.3v3.1EPSS5.27%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

artica pandora_fms Improper Input Validation

Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the /pandora_console/ajax.php ajax endpoint.

CWE-20Jun 15, 20181 related artifact
CVSS7.5v3.0EPSS6.53%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX