Impact
Unsanitized concatenation of the module parameter in the Grafana datasource endpoint (query.php) permits authenticated users to perform blind SQL injection. This flaw allows an attacker with valid credentials to inject arbitrary SQL statements into the database, potentially extracting sensitive data or manipulating stored information without immediate error responses. The vulnerability is classified as CWE-89, which covers SQL injection weaknesses.
Affected Systems
Pandora FMS is affected starting with version 777 and any build that follows until patched. The vendor has addressed the issue in releases 800.6 and 805, so any system running a version prior to those should apply the update to mitigate the risk.
Risk and Exploitability
The CVSS score of 7.2 denotes a high severity, and while no EPSS score is publicly available, the lack of listing in the CISA KEV catalog suggests current exploitation is not confirmed. Nevertheless, the requirement of authentication and the potential for data compromise imply that the vulnerability can be leveraged by an insider or compromised user, so assessment and remediation should proceed promptly.
OpenCVE Enrichment