PT-2021-20382 · Unknown · Pandora Fms

K4M1Ll0

+1

·

Published

2021-06-25

·

Updated

2021-07-01

·

CVE-2021-34074

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: PandoraFMS versions prior to 7.55
Description: The issue allows for arbitrary file upload, which can lead to remote command execution via the File Manager. This is achieved by using a relative path in the requests to bypass the built-in protection.
Recommendations: For versions prior to 7.55, update to version 7.55 or later to resolve the issue. As a temporary workaround, consider restricting access to the File Manager to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-34074

Affected Products

Pandora Fms