CVE-2018-11221

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
16/06/2018
Last modified:
14/08/2018

Description

Unauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an attacker to upload an arbitrary plugin via include/ajax/update_manager.ajax in the update system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:artica:pandora_fms:*:*:*:*:*:*:*:* 7.23 (including)