6.7
CVE-2023-41793
- EPSS 0.39%
- Veröffentlicht 19.03.2024 17:15:08
- Zuletzt bearbeitet 16.09.2025 15:15:05
- Quelle security@pandorafms.com
- CVE-Watchlists
- Unerledigt
Path Traversal and Untrusted Upload File
: Path Traversal vulnerability in Pandora FMS on all allows Path Traversal. This vulnerability allowed changing directories and creating files and downloading them outside the allowed directories. This issue affects Pandora FMS: from 700 through <776.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Artica ≫ Pandora Fms Version >= 700 < 776
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.39% | 0.305 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
| security@pandorafms.com | 6.7 | 1.2 | 5.5 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L
|
CWE-35 Path Traversal: '.../...//'
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.
https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/