Improper Neutralization of Special Elements in the backup name field may allow OS command injection. This issue affects Pandora ITSM 5.0.105.
History

Tue, 10 Jun 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 10 Jun 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements in the backup name field may allow OS command injection. This issue affects Pandora ITSM 5.0.105.
Title Remote Code Execution leads to Command Injection
Weaknesses CWE-77
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L/S:N/AU:N/R:U/V:D/RE:M/U:Green'}


cve-icon MITRE

Status: PUBLISHED

Assigner: PandoraFMS

Published: 2025-06-10T15:53:22.364Z

Updated: 2025-06-10T18:11:02.730Z

Reserved: 2025-05-13T13:42:23.568Z

Link: CVE-2025-4653

cve-icon Vulnrichment

Updated: 2025-06-10T16:03:24.302Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-10T16:15:42.607

Modified: 2025-06-12T16:06:39.330

Link: CVE-2025-4653

cve-icon Redhat

No data.