Vulnerabilities > Pandorafms > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-10-22 | CVE-2024-35308 | Path Traversal vulnerability in Pandorafms Pandora FMS 742/746 A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. This issue affects Pandora FMS: from 700 through <777.3. | 8.8 |
2024-10-22 | CVE-2024-9987 | SQL Injection vulnerability in Pandorafms Pandora FMS 742/746 A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv functionality. This issue affects Pandora FMS: from 700 through <777.3. | 8.8 |
2023-12-29 | CVE-2023-44088 | SQL Injection vulnerability in Pandorafms Pandora FMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitrary SQL queries were allowed to be executed using any account with low privileges. This issue affects Pandora FMS: from 700 through 774. | 8.8 |
2023-10-03 | CVE-2023-24518 | Cross-Site Request Forgery (CSRF) vulnerability in Pandorafms Pandora FMS A Cross-site Request Forgery (CSRF) vulnerability in Pandora FMS allows an attacker to force authenticated users to send a request to a web application they are currently authenticated against. | 7.1 |
2023-08-22 | CVE-2023-24517 | Unspecified vulnerability in Pandorafms Pandora FMS Unrestricted Upload of File with Dangerous Type vulnerability in the Pandora FMS File Manager component, allows an attacker to make make use of this issue ( unrestricted file upload ) to execute arbitrary system commands. | 7.2 |
2022-08-01 | CVE-2022-26309 | Cross-Site Request Forgery (CSRF) vulnerability in Pandorafms Pandora FMS Pandora FMS v7.0NG.759 allows Cross-Site Request Forgery in Bulk operation (User operation) resulting in elevation of privilege to Administrator group. | 8.8 |
2022-08-01 | CVE-2022-26310 | Unspecified vulnerability in Pandorafms Pandora FMS Pandora FMS v7.0NG.760 and below allows an improper authorization in User Management where any authenticated user with access to the User Management module could create, modify or delete any user with full admin privilege. | 8.8 |
2022-07-26 | CVE-2022-1648 | Path Traversal vulnerability in Pandorafms Pandora FMS Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intended images directory which is restricted to execute the .php file. | 7.2 |
2022-03-10 | CVE-2022-0507 | SQL Injection vulnerability in Pandorafms Pandora FMS Found a potential security vulnerability inside the Pandora API. | 8.8 |
2020-06-11 | CVE-2020-13855 | Unrestricted Upload of File with Dangerous Type vulnerability in Pandorafms Pandora FMS 7.44 Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Repository Manager feature. | 7.2 |