CVE-2021-32099
A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass.
Date published : 2021-05-06
https://blog.sonarsource.com/pandora-fms-742-critical-code-vulnerabilities-explained
