CVE-2020-5844 is a critical vulnerability affecting Pandora FMS v7.0 NG, specifically version 7.0NG.742_FIX_PERL2020, allowing authenticated administrators to achieve Remote Code Execution (RCE). The vulnerability stems from improper handling of file uploads, where malicious PHP scripts can be uploaded and executed via base64 decoding of their location. With a CVSS score of 7.2 (High), this flaw presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. While not listed on CISA's KEV catalog or having widespread community discussion, a public exploit (EDB-50961) exists, indicating its exploitability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0_ngCPE matchmatch criteria | cpe:2.3:a:artica:pandora_fms:7.0_ng:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.