First published: Fri Jun 25 2021(Updated: )
PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a relative path is used in the requests.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pandorafms Pandora Fms | <=754 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34074 is a vulnerability in PandoraFMS version 7.54 that allows arbitrary file upload, leading to remote command execution.
CVE-2021-34074 can be exploited by uploading a file using the File Manager feature and using a relative path in the request to bypass built-in protection.
CVE-2021-34074 has a severity rating of 9.8, which is considered critical.
PandoraFMS version <=7.54 is affected by CVE-2021-34074.
At the time of writing, there is no known fix or patch available for CVE-2021-34074. It is recommended to update to a version that is not affected by this vulnerability, if available.