7.2
CVE-2023-24517
- EPSS 0.95%
- Veröffentlicht 22.08.2023 19:16:34
- Zuletzt bearbeitet 21.11.2024 07:48:02
- Quelle cve-coordination@incibe.es
- CVE-Watchlists
- Unerledigt
Remote Code Execution via Unrestricted File Upload
Unrestricted Upload of File with Dangerous Type vulnerability in the Pandora FMS File Manager component, allows an attacker to make make use of this issue ( unrestricted file upload ) to execute arbitrary system commands. This issue affects Pandora FMS v767 version and prior versions on all platforms.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pandorafms ≫ Pandora Fms Version <= 767
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.95% | 0.564 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| cve-coordination@incibe.es | 6.4 | 0.9 | 5.5 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/
https://gist.github.com/Argonx21/9ab62f6e5d8bc6d39b8a338426af121e