Description
PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a relative path is used in the requests.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-20744 | PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a relative path is used in the requests. |
References
| Link | Providers |
|---|---|
| https://k4m1ll0.com/cve-pandorafms754-chained-xss-rce.html |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T00:05:52.239Z
Reserved: 2021-06-07T00:00:00.000Z
Link: CVE-2021-34074
No data.
Status : Modified
Published: 2021-06-25T16:15:17.120
Modified: 2024-11-21T06:09:52.680
Link: CVE-2021-34074
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD