CVE-2018-11222: Input Validation
Published Jun 15, 2018
·Updated
Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the /pandoraconsole/ajax.php ajax endpoint.
Affected Software
1 affected component
Artica Pandora FMS<=7.23
Event History
Jun 15, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability identified as CVE-2018-11222?
CVE-2018-11222 is a Local File Inclusion (LFI) vulnerability in Artica Pandora FMS through version 7.23.
2
What is the impact of CVE-2018-11222?
CVE-2018-11222 allows an attacker to call any php file via the /pandora_console/ajax.php ajax endpoint.
3
How can an attacker exploit CVE-2018-11222?
An attacker can exploit CVE-2018-11222 by manipulating the ajax.php endpoint to call arbitrary php files.
4
What is the severity of CVE-2018-11222?
The severity of CVE-2018-11222 is high, with a CVSS score of 7.5.
5
How can I mitigate CVE-2018-11222?
To mitigate CVE-2018-11222, it is recommended to upgrade Artica Pandora FMS to version 7.23 or higher.