Impact
A chained CSRF bypass combined with an unrestricted file upload flaw in the File Manager plugin enables an attacker to upload and run arbitrary PHP code. This results in full remote code execution, compromising confidentiality, integrity, and availability of the affected system. The vulnerability stems from missing CSRF protection and inadequate file type validation, as reflected by the CWE-352 and CWE-434 identifiers.
Affected Systems
The flaw impacts Pandora FMS installations from version 777 onward, specifically when the File Manager plugin is enabled. The vulnerability is limited to this plugin and does not affect other components of Pandora FMS.
Risk and Exploitability
The CVSS score of 7.5 classifies the issue as high severity, and the lack of an EPSS score indicates no available exploitation probability data; however, since the vulnerability is accessible via web requests, the attack vector is likely remote. The attack does not require privileged access, and the impact is severe, granting full code execution on the affected server. The vulnerability is not currently listed in the CISA KEV catalog, but its potential for widespread compromise warrants prompt action.
OpenCVE Enrichment