vendor:
Pandora FMS
by:
Matthew Aberegg, Alex Prieto
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Pandora FMS
Affected Version From: Pandora FMS 7.0 NG 750
Affected Version To: Pandora FMS 7.0 NG 750
Patch Exists: YES
Related CWE: N/A
CPE: a:pandorafms:pandora_fms:7.0_ng_750
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 18.04
2020
Pandora FMS 7.0 NG 750 – ‘Network Scan’ SQL Injection (Authenticated)
A blind SQL injection vulnerability exists in the 'Network Scan' functionality of Pandora FMS. The vulnerable parameter is 'network_csv'.
Mitigation:
The vendor has released a patch to address this vulnerability.