Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://blog.sonarsource.com/pandora-fms-742-critical-code-vulnerabilities-explained | third party advisory exploit |
https://pandorafms.com/blog/whats-new-in-pandora-fms-743/ | release notes vendor advisory |
https://portswigger.net/daily-swig/multiple-vulnerabilities-in-pandora-fms-could-trigger-remote-execution-attack | third party advisory exploit |