SQL Injection Vulnerability in Pandora FMS by Pandora FMS
CVE-2014-125115
Key Information:
- Vendor
Artica St
- Status
- Vendor
- CVE Published:
- 25 July 2025
Badges
What is CVE-2014-125115?
An unauthenticated SQL injection vulnerability exists in Pandora FMS versions prior to 5.0 SP3, specifically within the mobile/index.php endpoint. Attackers can exploit this flaw by manipulating the loginhash_data parameter, which is inadequately sanitized, leading to unauthorized extraction of administrator credentials and session tokens. Additionally, this vulnerability facilitates a further risk through the File Manager component, where arbitrary PHP file uploads are permitted without stringent MIME-type or file extension checks. This enables authenticated users to upload malicious web shells to publicly accessible directories, resulting in potential remote code execution.
Affected Version(s)
Pandora FMS * <= 5.0 SP2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved