CVE-2020-8497
artica pandora_fms Missing Authentication for Critical Function
Record summary
CVE-2020-8497 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format and it contains user names, user IDs, private messages, and timestamps.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 8, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
pandora_fmsBrowse artica / pandora_fms | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMArtica Pandora FMS <=7.42 - Arbitrary File ReadCVSS 5.3
Artica Pandora FMS through 7.42 is susceptible to arbitrary file read. An attacker can read the chat history, which is in JSON format and contains user names, user IDs, private messages, and timestamps. This can potentially lead to unauthorized data modification and other operations.
Impact
An attacker can exploit this vulnerability to gain unauthorized access to sensitive information, potentially leading to further compromise of the system.
Remediation
Upgrade Artica Pandora FMS to version 7.43 or later to mitigate this vulnerability.
Source: ProjectDiscovery