CVE-2025-4678: Pandora Fms Pandora Itsm
High severity, CVSS 7.0. EPSS: 1.5% chance of exploitation in the next 30 days.
Improper Neutralization of Special Elements in the chromium_path variable may allow OS command injection. This issue affects Pandora ITSM 5.0.105.
Affected products
- Pandora Fms Pandora Itsm: from 5.0.105, before 5.0.106 (fixed in 5.0.106)
Published 2025-06-10. Last modified 2026-06-17.