OS Command Injection Vulnerability in Pandora ITSM from Pandora FMS
CVE-2025-4678

7HIGH

Key Information:

Vendor
CVE Published:
10 June 2025

What is CVE-2025-4678?

A vulnerability in Pandora ITSM allows for OS command injection due to improper handling of the chromium_path variable. This can potentially lead to unauthorized command execution on the server, compromising the system's integrity and security. It is critical to apply necessary mitigations and updates to protect against such vulnerabilities.

Affected Version(s)

Pandora ITSM all 5.0.105 < 5.0.106

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

h00die-gr3y ([email protected])
.