VYPR

Pandorafms

by Pandorafms

Source repositories

CVEs (7)

  • CVE-2014-125124CriJul 31, 2025
    risk 0.68cvss epss 0.01

    An unauthenticated remote command execution vulnerability exists in Pandora FMS versions up to and including 5.0RC1 via the Anyterm web interface, which listens on TCP port 8023. The anyterm-module endpoint accepts unsanitized user input via the p parameter and directly injects…

  • CVE-2014-125115CriJul 25, 2025
    risk 0.68cvss epss 0.02

    An unauthenticated SQL injection vulnerability exists in Pandora FMS version 5.0 SP2 and earlier. The mobile/index.php endpoint fails to properly sanitize user input in the loginhash_data parameter, allowing attackers to extract administrator credentials or active session tokens…

  • CVE-2021-34074CriJun 25, 2021
    risk 0.64cvss 9.8epss 0.07

    PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a relative path is used in the requests.

  • CVE-2018-11221CriJun 16, 2018
    risk 0.64cvss 9.8epss 0.06

    Unauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an attacker to upload an arbitrary plugin via include/ajax/update_manager.ajax in the update system.

  • CVE-2021-35501MedJun 25, 2021
    risk 0.35cvss 5.4epss 0.01

    PandoraFMS <=7.54 allows Stored XSS by placing a payload in the name field of a visual console. When a user or an administrator visits the console, the XSS payload will be executed.

  • CVE-2019-19968MedFeb 4, 2020
    risk 0.35cvss 5.4epss 0.01

    PandoraFMS 742 suffers from multiple XSS vulnerabilities, affecting the Agent Management, Report Builder, and Graph Builder components. An authenticated user can inject dangerous content into a data store that is later read and included in dynamic content.

  • CVE-2018-11223MedJun 16, 2018
    risk 0.35cvss 5.4epss 0.01

    XSS in Artica Pandora FMS before 7.0 NG 723 allows an attacker to execute arbitrary code via a crafted "refr" parameter in a "/pandora_console/index.php?sec=estado&sec2=operation/agentes/estado_agente&refr=" call.