OS Command Injection Vulnerability in Pandora ITSM from Pandora FMS
CVE-2025-4678
7HIGH
What is CVE-2025-4678?
A vulnerability in Pandora ITSM allows for OS command injection due to improper handling of the chromium_path variable. This can potentially lead to unauthorized command execution on the server, compromising the system's integrity and security. It is critical to apply necessary mitigations and updates to protect against such vulnerabilities.
Affected Version(s)
Pandora ITSM all 5.0.105 < 5.0.106
References
CVSS V4
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
h00die-gr3y ([email protected])