CVE-2022-0507: Vulnerability: Authenticated SQL Injection in API
Published Mar 9, 2022
·Updated
Found a potential security vulnerability inside the Pandora API. Affected Pandora FMS version range: all versions of NG version, up to OUM 759. This vulnerability could allow an attacker with authenticated IP to inject SQL.
Affected Software
1 affected component
PandoraFMS Pandora FMS<760
Remediation
Information
Fixed in version v760
Event History
Mar 9, 2022
CVE Published
via MITRE·03:09 PM
Data Sourced
via MITRE·03:09 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-0507?
The severity of CVE-2022-0507 is high.
2
What is the affected software for CVE-2022-0507?
The affected software for CVE-2022-0507 is Pandora FMS versions up to OUM 759.
3
What is the vulnerability type for CVE-2022-0507?
The vulnerability type for CVE-2022-0507 is SQL injection.
4
How can an attacker exploit CVE-2022-0507?
An attacker with authenticated IP can exploit CVE-2022-0507 by injecting SQL.
5
Are there any resources available for CVE-2022-0507?
Yes, you can find more information about CVE-2022-0507 in the references provided: https://khoori.org/posts/cve-2022-0507/, https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/, and https://www.incibe.es/en/cve-assignment-publication/coordinated-cves.