CVE-2023-24517: Remote Code Execution via Unrestricted File Upload
Published Aug 22, 2023
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in the Pandora FMS File Manager component, allows an attacker to make make use of this issue ( unrestricted file upload ) to execute arbitrary system commands. This issue affects Pandora FMS v767 version and prior versions on all platforms.
Affected Software
1 affected component
PandoraFMS Pandora FMS<=767
Remediation
Information
Fixed in v769
Event History
Aug 22, 2023
CVE Published
via MITRE·01:05 PM
Data Sourced
via MITRE·01:05 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-24517?
The severity of CVE-2023-24517 is critical with a rating of 9.8 out of 10.
2
How does the Pandora FMS File Manager vulnerability CVE-2023-24517 affect the system?
The vulnerability allows attackers to upload and execute arbitrary system commands.
3
Which versions of Pandora FMS are affected by CVE-2023-24517?
Pandora FMS v767 version and prior versions are affected by this vulnerability.
4
How can an attacker exploit the CVE-2023-24517 vulnerability?
Attackers can exploit the vulnerability by uploading files with dangerous types and executing malicious commands.
5
Is there a fix available for the Pandora FMS File Manager vulnerability CVE-2023-24517?
It is recommended to update to a version higher than v767 to mitigate the vulnerability.