Post-Authentication SQL Injection Vulnerability Affects Pandora FMS
CVE-2024-9987

8.8HIGH

Key Information:

Vendor
CVE Published:
22 October 2024

What is CVE-2024-9987?

The vulnerability identified within the filters parameter of the extensions/agents_modules_csv functionality in Pandora FMS allows for post-authentication SQL Injection attacks. This security flaw impacts versions of Pandora FMS from 700 to below 777.3. Successful exploitation could enable attackers to manipulate SQL queries that the application executes, potentially leading to unauthorized access to sensitive data. Users are urged to review the implications of this vulnerability and mitigate risks accordingly.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.