CVE-2021-34074: Malicious File Upload
PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a relative path is used in the requests.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-34074?
CVE-2021-34074 is a vulnerability in PandoraFMS version 7.54 that allows arbitrary file upload, leading to remote command execution.
How can CVE-2021-34074 be exploited?
CVE-2021-34074 can be exploited by uploading a file using the File Manager feature and using a relative path in the request to bypass built-in protection.
What is the severity of CVE-2021-34074?
CVE-2021-34074 has a severity rating of 9.8, which is considered critical.
What is the affected software version for CVE-2021-34074?
PandoraFMS version <=7.54 is affected by CVE-2021-34074.
Is there a fix available for CVE-2021-34074?
At the time of writing, there is no known fix or patch available for CVE-2021-34074. It is recommended to update to a version that is not affected by this vulnerability, if available.