HIGH

CVE-2020-5844

CVSS v3

7.2

HIGH

EPSS Score

73.8%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts, and execute them via base64 decoding of the file location. This affects v7.0NG.742_FIX_PERL2020.

Technical details

Published
3/16/2020

Frequently asked questions

What is CVE-2020-5844?

index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts, and execute them via base64 decoding of the file location. This affects v7.0NG.742_FIX_PERL2020.

Is CVE-2020-5844 actively exploited?

Active exploitation of CVE-2020-5844 has not been confirmed. The EPSS score is 73.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-5844?

CVE-2020-5844 has a CVSS v3 base score of 7.2 (HIGH severity).

Is CVE-2020-5844 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.