vendor:
Pandora FMS
by:
Manuel Mancera (sinkmanu)
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Pandora FMS
Affected Version From: 5
Affected Version To: 5.1
Patch Exists: YES
Related CWE: N/A
CPE: pandorafms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2015
Authentication Bypass in Pandora FMS
A vulnerability has been discovered in Pandora FMS that permits an unautheticated user to change the password for any Pandora user without knowing the actual user password. The vulnerability occurs at the login screen due to the session not being checked before the password is changed.
Mitigation:
Apply the latest patches available at the vendor website.