CVE-2023-41786 MEDIUM

CVE-2023-41786: Database backups availability by low-privileged users

Vendor Pandora Fms
Product Pandora FMS
Weakness CWE-200 · Info exposure
Published November 23, 2023
Last update October 15, 2024

CVSS base score

6.8/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

What the vulnerability does

01Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pandora FMS on all allows File Discovery. This vulnerability allows users with low privileges to download database backups. This issue affects Pandora FMS: from 700 through 772.

Key dates

02Disclosure timeline

November 23, 2023 CVE published
October 15, 2024 Record updated