Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs directory for cron log backups. The contents of these log files can then be abused to authenticate to the application as an administrator. This issue affects Pandora FMS <= 772.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: PandoraFMS

Published: 2023-11-23T14:22:01.559Z

Updated: 2024-08-02T07:31:06.635Z

Reserved: 2023-08-31T15:38:14.018Z

Link: CVE-2023-4677

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-11-23T15:15:10.410

Modified: 2023-11-30T17:06:24.530

Link: CVE-2023-4677

cve-icon Redhat

No data.