Vulnerability Description
A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Artica | Pandora Fms | 742 |
Related Weaknesses (CWE)
References
- https://blog.sonarsource.com/pandora-fms-742-critical-code-vulnerabilities-explaExploitThird Party Advisory
- https://pandorafms.com/blog/whats-new-in-pandora-fms-743/Release NotesVendor Advisory
- https://portswigger.net/daily-swig/multiple-vulnerabilities-in-pandora-fms-couldExploitThird Party Advisory
- https://blog.sonarsource.com/pandora-fms-742-critical-code-vulnerabilities-explaExploitThird Party Advisory
- https://pandorafms.com/blog/whats-new-in-pandora-fms-743/Release NotesVendor Advisory
- https://portswigger.net/daily-swig/multiple-vulnerabilities-in-pandora-fms-couldExploitThird Party Advisory
FAQ
What is CVE-2021-32099?
CVE-2021-32099 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php ses...
How severe is CVE-2021-32099?
CVE-2021-32099 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-32099?
Check the references section above for vendor advisories and patch information. Affected products include: Artica Pandora Fms.