CVE-2019-20224: Artica Pandora Fms
High severity, CVSS 8.8. EPSS: 49.7% chance of exploitation in the next 30 days.
netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request. This issue has been fixed in Pandora FMS 7.0 NG 742.
Affected products
- Artica Pandora Fms: version 7.0_ng only
Published 2020-01-09. Last modified 2026-06-17.