CVE-2022-1648: Pandorafms Pandora Fms
High severity, CVSS 7.2. EPSS: 1.3% chance of exploitation in the next 30 days.
Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intended images directory which is restricted to execute the .php file. The impact could lead to a Remote Code Execution with running application privilege.
Affected products
- Pandorafms Pandora Fms: up to and including 7.0_ng_760
Published 2022-07-26. Last modified 2026-06-17.