Description
Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intended images directory which is restricted to execute the .php file. The impact could lead to a Remote Code Execution with running application privilege.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Fixed in v761
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-24935 | Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intended images directory which is restricted to execute the .php file. The impact could lead to a Remote Code Execution with running application privilege. |
References
History
No history.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-09-16T19:47:11.391Z
Reserved: 2022-05-10T00:00:00.000Z
Link: CVE-2022-1648
No data.
Status : Modified
Published: 2022-07-26T15:15:10.513
Modified: 2024-11-21T06:41:10.350
Link: CVE-2022-1648
No data.
OpenCVE Enrichment
No data.
EUVD