CVE-2018-11222

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
16/06/2018
Last modified:
14/08/2018

Description

Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the /pandora_console/ajax.php ajax endpoint.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:artica:pandora_fms:*:*:*:*:*:*:*:* 7.23 (including)