OS Command Injection Vulnerability in Pandora ITSM by Pandora FMS
CVE-2025-4653
7HIGH
What is CVE-2025-4653?
An OS command injection vulnerability exists in the backup name field of Pandora ITSM 5.0.105 due to improper neutralization of special elements. This flaw may enable an attacker to execute arbitrary commands on the operating system, potentially compromising the security of the system.
Affected Version(s)
Pandora ITSM all 5.0.105 < 5.0.106
References
CVSS V4
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
h00die-gr3y ([email protected])