PT-2023-19664 · Unknown · Pandora Fms

Published

2023-08-22

·

Updated

2023-11-02

·

CVE-2023-24517

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pandora FMS versions prior to 7.67
Description The issue allows an attacker to execute arbitrary system commands by exploiting an unrestricted file upload vulnerability in the Pandora FMS File Manager component.
Recommendations For versions prior to 7.67, update to version 7.67 or later to resolve the issue.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2023-24517

Affected Products

Pandora Fms