Vulnerability Description
PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a relative path is used in the requests.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pandorafms | Pandora Fms | <= 754 |
Related Weaknesses (CWE)
References
- https://k4m1ll0.com/cve-pandorafms754-chained-xss-rce.htmlExploitThird Party Advisory
- https://k4m1ll0.com/cve-pandorafms754-chained-xss-rce.htmlExploitThird Party Advisory
FAQ
What is CVE-2021-34074?
CVE-2021-34074 is a vulnerability with a CVSS score of 9.8 (CRITICAL). PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a relative path is used in the requests.
How severe is CVE-2021-34074?
CVE-2021-34074 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-34074?
Check the references section above for vendor advisories and patch information. Affected products include: Pandorafms Pandora Fms.