OS Command Injection Vulnerability in Pandora ITSM by Pandora FMS
CVE-2025-4653

7HIGH

Key Information:

Vendor
CVE Published:
10 June 2025

What is CVE-2025-4653?

An OS command injection vulnerability exists in the backup name field of Pandora ITSM 5.0.105 due to improper neutralization of special elements. This flaw may enable an attacker to execute arbitrary commands on the operating system, potentially compromising the security of the system.

Affected Version(s)

Pandora ITSM all 5.0.105 < 5.0.106

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

h00die-gr3y ([email protected])
.