Back

HIGH

Relative Path Traversal to Remote Code Execution in File Manager

Published Jul 26, 2022

Description

Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intended images directory which is restricted to execute the .php file. The impact could lead to a Remote Code Execution with running application privilege.

Affected products

Remediation

Vendor solution

Fixed in v761

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner INCIBE
Published Jul 26, 2022
Updated Sep 16, 2024
Reserved May 10, 2022

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner INCIBE
Published Jul 26, 2022
Updated Sep 16, 2024

GitHub

No data