PT-2020-18753 · Artica · Pandora Fms
Thecybergeek
·
Published
2020-03-16
·
Updated
2022-11-29
·
CVE-2020-5844
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pandora FMS version 7.0NG.742 FIX PERL2020
Description
The issue allows authenticated administrators to upload malicious PHP scripts and execute them via base64 decoding of the file location. This is achieved through the
index.php?sec=godmode/extensions&sec2=extensions/files repo endpoint.Recommendations
For version 7.0NG.742 FIX PERL2020, consider restricting access to the
index.php?sec=godmode/extensions&sec2=extensions/files repo endpoint to prevent malicious script uploads until a patch is available. As a temporary workaround, disabling the ability to upload files via this endpoint can minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pandora Fms