Back to directory
WRITEUP #605

Technical Advisory – Multiple Vulnerabilities in PandoraFMS Enterprise

Auth BypassAccount takeoverInformation disclosureRCEUnrestricted file uploadStored XSSArbitrary file readLocal Privilege EscalationPath traversalDoSIDORHardcoded credentials
byOliver Brooks
Program
PandoraFMS
Published
Jan 2, 2024
Added to HackDex
Jan 8, 2024
Read Full Writeuphttps://research.nccgroup.com/2024/01/02/technical-advisory-multiple-vulnerabilities-in-pandorafms-enterprise/
RELATED WRITEUPS
Bucket Monopoly: Breaching AWS Accounts Through Shadow Resources
CloudRCE
Traccar 5 Remote Code Execution Vulnerabilities
RCEUnrestricted file upload
Interesting Story of an Account Takeover Vulnerability
Auth BypassAccount takeover
Analysis of CVE-2024-43044 — From file read to RCE in Jenkins through agents
RCEArbitrary file read
3CX Phone System Local Privilege Escalation Vulnerability
Privilege EscalationLocal Privilege Escalation

Built with ❤️ by Shubham Rawat