Impact
The vulnerability resides in the File Manager module of Pandora FMS. An incomplete extension blacklist permits an authenticated user to upload .phar files, which the system then executes. This flaw enables an attacker to run arbitrary code on the server, giving full control over the affected system. The weakness corresponds to CWE‑434: Unrestricted Upload of File with Dangerous Type.
Affected Systems
Pandora FMS versions 777 and later are impacted. The flaw is present in all releases from 777 up to the patched releases v800.5 and v805.
Risk and Exploitability
The vulnerability has a CVSS score of 8.6, indicating high severity. EPSS data is unavailable, and the issue is not currently listed in CISA KEV. Attacking requires valid authentication to the admin interface, after which an attacker can upload a malicious .phar and trigger execution. Because the flaw allows arbitrary code execution with elevated privileges, it poses a severe risk to confidentiality, integrity, and availability of the affected systems.
OpenCVE Enrichment