Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-1648


Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intended images directory which is restricted to execute the .php file. The impact could lead to a Remote Code Execution with running application privilege.


Published

2022-07-26T15:15:10.513

Last Modified

2024-11-21T06:41:10.350

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.7 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-23
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application pandorafms pandora_fms ≤ 7.0_ng_760 Yes

References