PT-2022-17779 · Unknown · Pandora Fms
Published
2022-08-01
·
Updated
2022-08-05
·
CVE-2022-26310
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Pandora FMS versions 7.0NG.760 and below
Description
The issue allows an improper authorization in User Management, where any authenticated user with access to the User Management module could create, modify, or delete any user with full admin privilege. This could lead to a vertical privilege escalation, allowing access to the privileges of a higher-level user or typically an admin user.
Recommendations
For Pandora FMS versions 7.0NG.760 and below, consider restricting access to the User Management module to prevent unauthorized modifications to user privileges until a fix is available. As a temporary workaround, limit the capabilities of users with access to the User Management module to minimize the risk of exploitation.
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pandora Fms