Impact
A missing authorization check in the get_module_detail AJAX endpoint allows a user to retrieve module history from any group to which they have no access. This can expose sensitive operational data and configuration settings across organizational boundaries. The flaw is a pure confidentiality violation, not an integrity or availability concern.
Affected Systems
Pandora FMS software, versions 777 and newer. The vulnerability applies to all releases of Pandora FMS that contain the get_module_detail endpoint, including the 800.5 and 804 builds that contain the fix.
Risk and Exploitability
The CVSS score is 7.1, indicating a high severity. Since the EPSS score is not available, the current probability of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely via the Web interface, relying on user credentials or session tokens to bypass group boundaries. No special conditions or elevated privileges are required beyond access to the Web UI.
OpenCVE Enrichment