Security Advisory
CVE-2021-36697
6.7
MEDIUM
Vulnerability Description
With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file contains a Rewrite Rule with a type definition. A normal PHP file can be uploaded with this new "file type" and the code can be executed with an HTTP request.
Published Date
November 3, 2021
Official Source
NIST NVD Advisory