PT-2018-10405 · Artica · Artica Pandora Fms

Published

2018-06-15

·

Updated

2018-08-14

·

CVE-2018-11221

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Artica Pandora FMS versions prior to 7.23
Description The issue allows an attacker to perform an unauthenticated untrusted file upload. This is achieved through the update system, specifically via the "include/ajax/update manager.ajax" API endpoint. An attacker can upload an arbitrary plugin, potentially leading to further exploitation.
Recommendations For versions prior to 7.23, update to version 7.23 or later to resolve the issue. As a temporary workaround, consider restricting access to the "include/ajax/update manager.ajax" API endpoint to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-11221

Affected Products

Artica Pandora Fms