PT-2020-20179 · Artica · Artica Pandora Fms

K4M1Ll0

·

Published

2020-03-02

·

Updated

2024-08-04

·

CVE-2020-8500

CVSS v2.0
6.5
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P

Name of the Vulnerable Software and Affected Versions:

Artica Pandora FMS version 7.42

Description:

The issue allows Web Admin users to execute arbitrary code by uploading a .php file via the Updater or Extension component. However, the vendor reports that this functionality is intended.

Recommendations:

For Artica Pandora FMS version 7.42, consider restricting access to the Updater or Extension component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2020-8500

Affected Products

Artica Pandora Fms