PT-2024-2985 · Unknown · Pandora Fms

Aleksey Solovev

·

Published

2024-01-10

·

Updated

2024-03-20

·

CVE-2023-44091

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pandora FMS versions 700 through 775
Description The issue is related to an SQL Injection vulnerability due to improper neutralization of special elements used in an SQL command. This allows an attacker to perform SQL injections even if authentication fails, potentially leading to unauthorized access to protected information and the execution of arbitrary SQL code.
Recommendations For Pandora FMS versions 700 through 775, update to a version that includes a fix for this SQL Injection vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2024-03165
CVE-2023-44091

Affected Products

Pandora Fms