CVE-2024-35305: Unauth Time-Based SQL Injection via API
Published Jun 10, 2024
·Updated
Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora FMS: from 700 through <777.
Affected Software
2 affected components
Pandora FMS Pandora FMS>=700<777
Artica Pandora FMS>=700<777
Remediation
Information
Fixed in v777
Event History
Jun 10, 2024
CVE Published
via MITRE·02:28 PM
Data Sourced
via MITRE·02:28 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-35305?
CVE-2024-35305 is considered a high severity vulnerability due to its potential for exploiting SQL injection via the API.
2
How do I fix CVE-2024-35305?
To fix CVE-2024-35305, it is recommended to update Pandora FMS to a version higher than 777.
3
What software versions are affected by CVE-2024-35305?
CVE-2024-35305 affects Pandora FMS versions from 700 to 777.
4
What type of vulnerability is CVE-2024-35305?
CVE-2024-35305 is classified as an unauthenticated time-based SQL injection vulnerability.
5
Can CVE-2024-35305 be exploited remotely?
Yes, CVE-2024-35305 can be exploited remotely through manipulated HTTP request headers.