PT-2018-10406 · Artica · Artica Pandora Fms

Published

2018-06-15

·

Updated

2018-08-14

·

CVE-2018-11222

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Artica Pandora FMS versions prior to 7.23
Description The issue allows an attacker to perform a Local File Inclusion (LFI) attack. This is achieved by calling any php file via the "/pandora console/ajax.php" API endpoint.
Recommendations For versions prior to 7.23, update to version 7.23 or later to resolve the issue.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-11222

Affected Products

Artica Pandora Fms