CVE-2023-41812: Uploading executables via the file manager
Published Nov 23, 2023
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in Pandora FMS on all allows Accessing Functionality Not Properly Constrained by ACLs. This vulnerability allowed PHP executable files to be uploaded through the file manager. This issue affects Pandora FMS: from 700 through 773.
Affected Software
1 affected component
Artica Pandora FMS>=700<774
Remediation
Information
Fixed in v774 and v772.2.
Event History
Nov 23, 2023
CVE Published
02:58 PM
Data Sourced
02:58 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2023-41812.
2
What is the severity score of CVE-2023-41812?
The severity score of CVE-2023-41812 is 8.8 (High).
3
What is the affected software of CVE-2023-41812?
The affected software of CVE-2023-41812 is Pandora FMS version 700 through 773.
4
What is the description of CVE-2023-41812?
CVE-2023-41812 is a vulnerability in Pandora FMS that allows the unrestricted upload of PHP executable files through the file manager.
5
Is there a fix available for CVE-2023-41812?
The fix for CVE-2023-41812 is not mentioned in the provided information. Please refer to the provided reference link for more information.