CVE-2024-9987: SQL Injection in CSV Module Data Collection
Published Oct 22, 2024
·Updated
A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agentsmodulescsv functionality. This issue affects Pandora FMS: from 700 through <777.3.
Affected Software
1 affected component
PandoraFMS Pandora FMS>=700<=777.3
Remediation
Information
Update version 777.3
Event History
Oct 22, 2024
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-9987?
CVE-2024-9987 is considered a critical severity vulnerability due to its potential impact through SQL Injection.
2
How do I fix CVE-2024-9987?
To fix CVE-2024-9987, upgrade Pandora FMS to a version later than 777.3.
3
What systems are affected by CVE-2024-9987?
CVE-2024-9987 affects Pandora FMS versions from 700 to 777.3.
4
What type of vulnerability is CVE-2024-9987?
CVE-2024-9987 is a post-authentication SQL Injection vulnerability.
5
Can CVE-2024-9987 be exploited remotely?
Yes, CVE-2024-9987 can potentially be exploited remotely if the attacker has authentication credentials.