CVE-2020-8497

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
23/03/2020
Last modified:
21/07/2021

Description

In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format and it contains user names, user IDs, private messages, and timestamps.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:artica:pandora_fms:*:*:*:*:*:*:*:* 7.42 (including)


References to Advisories, Solutions, and Tools