CVE-2024-12971
HIGHPandora FMS authenticated command injection leading to RCE via chromium_path or phantomjs_bin
Title source: metasploitExploitation Summary
EIP tracks 1 public exploit for CVE-2024-12971.
Includes Metasploit module exploits/linux/http/pandora_fms_auth_rce_cve_2024_12971.
AI-analyzed exploit summary This Metasploit module exploits an authenticated command injection vulnerability in Pandora FMS via the `chromium_path` or `phantomjs_bin` settings, leading to remote code execution. It requires admin access, which can be obtained via default credentials or MySQL database manipulation.
Description
Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6
Exploits (1)
This Metasploit module exploits an authenticated command injection vulnerability in Pandora FMS via the `chromium_path` or `phantomjs_bin` settings, leading to remote code execution. It requires admin access, which can be obtained via default credentials or MySQL database manipulation.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H