First published: Sat Jun 16 2018(Updated: )
Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the /pandora_console/ajax.php ajax endpoint.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artica Pandora FMS | <=7.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11222 is a Local File Inclusion (LFI) vulnerability in Artica Pandora FMS through version 7.23.
CVE-2018-11222 allows an attacker to call any php file via the /pandora_console/ajax.php ajax endpoint.
An attacker can exploit CVE-2018-11222 by manipulating the ajax.php endpoint to call arbitrary php files.
The severity of CVE-2018-11222 is high, with a CVSS score of 7.5.
To mitigate CVE-2018-11222, it is recommended to upgrade Artica Pandora FMS to version 7.23 or higher.