CVE-2020-26518: SQL Injection
Published Oct 2, 2020
·Updated
Artica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandoraconsole/include/chartgenerator.php sessionid parameter.
Affected Software
1 affected component
Artica Pandora FMS<743
Event History
Oct 2, 2020
CVE Published
via MITRE·04:31 AM
Data Sourced
via MITRE·04:31 AM
Description
Frequently Asked Questions
1
What is CVE-2020-26518?
CVE-2020-26518 is a vulnerability in Artica Pandora FMS before version 743 that allows unauthenticated attackers to conduct SQL injection attacks.
2
How severe is CVE-2020-26518?
CVE-2020-26518 has a severity rating of critical, with a CVSS score of 9.8.
3
How can unauthenticated attackers exploit CVE-2020-26518?
Unauthenticated attackers can exploit CVE-2020-26518 by conducting SQL injection attacks through the session_id parameter in the pandora_console/include/chart_generator.php file.
4
What is the affected software by CVE-2020-26518?
The affected software is Artica Pandora FMS before version 743.
5
Is there a fix for CVE-2020-26518?
Yes, to fix CVE-2020-26518, it is recommended to upgrade to version 743 of Artica Pandora FMS.