HIGH
Relative Path Traversal to Remote Code Execution in File Manager
Published Jul 26, 2022
7.2
HIGHCVSS 3.1
EPSS 1.33%
Description
Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intended images directory which is restricted to execute the .php file. The impact could lead to a Remote Code Execution with running application privilege.
Affected products
-
Affected
- v760
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Artica PFMS | Pandora FMS | unknown | Affected
|
- ≤ 7.0_ng_760
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Fixed in v761
Weaknesses (2)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24935 Advisory
- https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/ x_refsource_CONFIRMVendor Advisory
- https://www.incibe.es/en/cve-assignment-publication/coordinated-cves x_refsource_CONFIRMThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24935 | Advisory | |
| https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/ | x_refsource_CONFIRMVendor Advisory | |
| https://www.incibe.es/en/cve-assignment-publication/coordinated-cves | x_refsource_CONFIRMThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Jul 26, 2022
Updated Sep 16, 2024
Reserved May 10, 2022
Link CVE-2022-1648
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data