vendor:
Pandora 7.0NG
by:
Askar
8.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Pandora 7.0NG
Affected Version From: 7.0NG
Affected Version To: 7.0NG
Patch Exists: YES
Related CWE: CVE-2019-20224
CPE: a:pandorafms:pandora_fms:7.0ng
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: CentOS 7.3 / PHP 5.4.16
2019
Pandora 7.0NG – Remote Code Execution
Pandora 7.0NG is vulnerable to a remote code execution vulnerability. An attacker can send a crafted graph request with a malicious ip_src parameter to execute arbitrary code on the vulnerable system. This vulnerability is due to insufficient sanitization of user-supplied input in the ip_src parameter of the graph request. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the vulnerable system.
Mitigation:
The vendor has released an update to address this vulnerability. Users are advised to update to the latest version of Pandora 7.0NG.