In Artica Pandora FMS 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the Updater or Extension component. NOTE: The vendor reports that this is intended functionality
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://k4m1ll0.com/cve-2020-8500.html | third party advisory exploit |
https://pandorafms.com/downloads/extension-uploader-feature-explained.mp4 |