CVE-2023-41790: Traversal Path on PHP file
Published Nov 23, 2023
·Updated
Uncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File Search Paths. This vulnerability allows to access the server configuration file and to compromise the database. This issue affects Pandora FMS: from 700 through 773.
Affected Software
1 affected component
Artica Pandora FMS>=700<=773
Remediation
Information
Fixed in v774 in v772.2.
Event History
Nov 23, 2023
CVE Published
02:38 PM
Data Sourced
02:38 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-41790.
2
What is the severity of the CVE-2023-41790 vulnerability?
The severity of the CVE-2023-41790 vulnerability is critical.
3
What does the CVE-2023-41790 vulnerability impact?
The CVE-2023-41790 vulnerability allows unauthorized access to the server configuration file and can compromise the database.
4
Which version of Pandora FMS is affected by the CVE-2023-41790 vulnerability?
The CVE-2023-41790 vulnerability affects Pandora FMS versions 700 through 773.
5
How can I fix the CVE-2023-41790 vulnerability?
To fix the CVE-2023-41790 vulnerability, apply the latest patches or updates provided by the vendor, Artica Pandora FMS.