PT-2020-6798 · Artica · Artica Pandora Fms

Dennis Brinkrolf

·

Published

2020-01-17

·

Updated

2025-07-19

·

CVE-2021-32099

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Artica Pandora FMS version 742
Description A SQL injection issue in the pandora console component allows an unauthenticated attacker to bypass login restrictions by exploiting the session id parameter in the "/include/chart generator.php" API endpoint. This vulnerability can be exploited remotely, enabling an attacker to execute arbitrary SQL code and upgrade an unprivileged session.
Recommendations For Artica Pandora FMS version 742, consider restricting access to the "/include/chart generator.php" API endpoint until a patch is available, and avoid using the session id parameter in this endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2022-06602
CVE-2021-32099

Affected Products

Artica Pandora Fms