Vulnerabilities > Pandorafms > High

DATE CVE VULNERABILITY TITLE RISK
2024-10-22 CVE-2024-35308 Path Traversal vulnerability in Pandorafms Pandora FMS 742/746
A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. This issue affects Pandora FMS: from 700 through <777.3.
network
low complexity
pandorafms CWE-22
8.8
2024-10-22 CVE-2024-9987 SQL Injection vulnerability in Pandorafms Pandora FMS 742/746
A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv functionality. This issue affects Pandora FMS: from 700 through <777.3.
network
low complexity
pandorafms CWE-89
8.8
2023-12-29 CVE-2023-44088 SQL Injection vulnerability in Pandorafms Pandora FMS
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitrary SQL queries were allowed to be executed using any account with low privileges. This issue affects Pandora FMS: from 700 through 774.
network
low complexity
pandorafms CWE-89
8.8
2023-10-03 CVE-2023-24518 Cross-Site Request Forgery (CSRF) vulnerability in Pandorafms Pandora FMS
A Cross-site Request Forgery (CSRF) vulnerability in Pandora FMS allows an attacker to force authenticated users to send a request to a web application they are currently authenticated against.
network
low complexity
pandorafms CWE-352
7.1
2023-08-22 CVE-2023-24517 Unspecified vulnerability in Pandorafms Pandora FMS
Unrestricted Upload of File with Dangerous Type vulnerability in the Pandora FMS File Manager component, allows an attacker to make make use of this issue ( unrestricted file upload ) to execute arbitrary system commands.
network
low complexity
pandorafms
7.2
2022-08-01 CVE-2022-26309 Cross-Site Request Forgery (CSRF) vulnerability in Pandorafms Pandora FMS
Pandora FMS v7.0NG.759 allows Cross-Site Request Forgery in Bulk operation (User operation) resulting in elevation of privilege to Administrator group.
network
low complexity
pandorafms CWE-352
8.8
2022-08-01 CVE-2022-26310 Unspecified vulnerability in Pandorafms Pandora FMS
Pandora FMS v7.0NG.760 and below allows an improper authorization in User Management where any authenticated user with access to the User Management module could create, modify or delete any user with full admin privilege.
network
low complexity
pandorafms
8.8
2022-07-26 CVE-2022-1648 Path Traversal vulnerability in Pandorafms Pandora FMS
Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intended images directory which is restricted to execute the .php file.
network
low complexity
pandorafms CWE-22
7.2
2022-03-10 CVE-2022-0507 SQL Injection vulnerability in Pandorafms Pandora FMS
Found a potential security vulnerability inside the Pandora API.
network
low complexity
pandorafms CWE-89
8.8
2020-06-11 CVE-2020-13855 Unrestricted Upload of File with Dangerous Type vulnerability in Pandorafms Pandora FMS 7.44
Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Repository Manager feature.
network
low complexity
pandorafms CWE-434
7.2