Pandora FMS SQL Injection Vulnerability Allows for Unauthorized File Modification
CVE-2023-44090

6.8MEDIUM

Key Information:

Vendor
CVE Published:
19 March 2024

What is CVE-2023-44090?

An SQL Injection vulnerability has been identified in Pandora FMS across multiple versions, which allows attackers to execute unauthorized SQL commands. This issue particularly affects the Grafana module of Pandora FMS, enabling potential manipulation of database content by leveraging improper neutralization of special elements in SQL commands. Affected versions range from 700 to below 776, highlighting the need for immediate attention and remediation to prevent exploitation.

Affected Version(s)

Pandora FMS all 700

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

.