Impact
This vulnerability is a CSRF flaw that allows an attacker who can get an authenticated administrator to visit a malicious page to send a sequence of unvalidated GET requests that delete alert commands. The result is the loss of critical monitoring configuration, potentially disrupting alerting and exposing sensitive data.
Affected Systems
Pandora FMS products from version 777 onward are affected. The vendor has issued fixes in version 800.5 and 805. Administrators running any of these releases should confirm their current version and plan an upgrade to a patched release.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and no EPSS score is available. Because the flaw is a CSRF attack that requires the target manager to load a malicious page while authenticated, the attack is constrained to social engineering or credential compromise scenarios. The vulnerability is not listed in the CISA KEV catalog, but the lack of a high CVSS or EPSS does not negate the risk of successful exploitation.
OpenCVE Enrichment