CVE-2021-32099: SQL Injection
Published May 7, 2021
·Updated
A SQL injection vulnerability in the pandoraconsole component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chartgenerator.php sessionid parameter, leading to a login bypass.
Affected Software
1 affected component
Artica Pandora FMS=742
Event History
May 7, 2021
CVE Published
via MITRE·03:51 AM
Data Sourced
via MITRE·03:51 AM
Description
Frequently Asked Questions
1
What is CVE-2021-32099?
CVE-2021-32099 is a SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742.
2
How severe is CVE-2021-32099?
CVE-2021-32099 is rated as critical with a severity score of 9.8.
3
How does CVE-2021-32099 impact Artica Pandora FMS 742?
CVE-2021-32099 allows an unauthenticated attacker to upgrade their unprivileged session, leading to a login bypass.
4
What is the affected software version of Artica Pandora FMS?
Artica Pandora FMS version 742 is affected by CVE-2021-32099.
5
How can I fix CVE-2021-32099?
To fix CVE-2021-32099, it is recommended to apply the latest security updates provided by Artica Pandora FMS.