First published: Sat Jun 16 2018(Updated: )
Unauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an attacker to upload an arbitrary plugin via include/ajax/update_manager.ajax in the update system.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artica Pandora FMS | <=7.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2018-11221.
The severity of CVE-2018-11221 is critical with a severity value of 9.8.
The affected software for CVE-2018-11221 is Artica Pandora FMS version 7.23.
CVE-2018-11221 allows an attacker to upload an arbitrary plugin via include/ajax/update_manager.ajax in the update system.
Yes, you can find references for CVE-2018-11221 at the following links: [Link 1](https://blog.hackercat.ninja/post/pandoras_box/) and [Link 2](https://pandorafms.com/wp-content/uploads/2018/06/whats-new-723-EN.pdf).