PT-2020-20179 · Artica · Artica Pandora Fms

K4M1Ll0

·

Published

2020-03-02

·

Updated

2024-08-04

·

CVE-2020-8500

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Artica Pandora FMS version 7.42
Description The issue allows Web Admin users to execute arbitrary code by uploading a .php file via the Updater or Extension component. However, the vendor reports that this functionality is intended.
Recommendations For Artica Pandora FMS version 7.42, consider restricting access to the Updater or Extension component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2020-8500

Affected Products

Artica Pandora Fms