Vulnerability Description
Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora FMS: from 700 through <777.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Artica | Pandora Fms | >= 700, < 777 |
Related Weaknesses (CWE)
References
- https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/Vendor Advisory
- https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/Vendor Advisory
FAQ
What is CVE-2024-35305?
CVE-2024-35305 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora FMS: from 700 through <777.
How severe is CVE-2024-35305?
CVE-2024-35305 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-35305?
Check the references section above for vendor advisories and patch information. Affected products include: Artica Pandora Fms.