nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-44088 CVE-2023-44088
MEDIUM
SQL Injection in Visual Console
Record summary
CVE-2023-44088 has a selected CVSS score of 5.9 (medium); EIP currently links 1 catalogued exploit.
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitrary SQL queries were allowed to be executed using any account with low privileges. This issue affects Pandora FMS: from 700 through 774.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 3, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Pandora FMSBrowse Pandora FMS / Pandora FMSDefault status: unaffected | CVE List | 700 to ≤ 774 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBPandoraFMS 7.0NG.772 - SQL InjectionExploitDB exploitby Osama YousefNot analyzed1 file
References
2pandorafms.comVendor advisory
https://pandorafms.com/en/security/common-vulnerabilities-and-exposures