CVE-2021-34074
25.06.2021, 16:15
PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a relative path is used in the requests.Enginsight
Vendor | Product | Version |
---|---|---|
pandorafms | pandora_fms | 𝑥 ≤ 754 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration