Security Advisory

CVE-2021-36697

6.7
MEDIUM

Vulnerability Description

With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file contains a Rewrite Rule with a type definition. A normal PHP file can be uploaded with this new "file type" and the code can be executed with an HTTP request.
Published Date November 3, 2021
Official Source NIST NVD Advisory