Vulnerability Description
In Artica Pandora FMS 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the Updater or Extension component. NOTE: The vendor reports that this is intended functionality
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Artica | Pandora Fms | 7.42 |
Related Weaknesses (CWE)
References
- https://k4m1ll0.com/cve-2020-8500.htmlExploitThird Party Advisory
- https://pandorafms.com/downloads/extension-uploader-feature-explained.mp4
- https://k4m1ll0.com/cve-2020-8500.htmlExploitThird Party Advisory
- https://pandorafms.com/downloads/extension-uploader-feature-explained.mp4
FAQ
What is CVE-2020-8500?
CVE-2020-8500 is a vulnerability with a CVSS score of 7.2 (HIGH). In Artica Pandora FMS 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the Updater or Extension component. NOTE: The vendor reports that this is intended functionality
How severe is CVE-2020-8500?
CVE-2020-8500 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8500?
Check the references section above for vendor advisories and patch information. Affected products include: Artica Pandora Fms.