← Vulnerability feed

Vulnerability record · CVE-2021-32099 · published 7 May 2021

CVE-2021-32099: Artica pandora fms sql injection vulnerability

Artica · Pandora Fms

A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass.

9.8 CVSS 3.1 Critical EPSS 13% · top 3.9% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-32099 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-4279Pandora FMS default config allows authentication bypassPandora FMS 3.1 and earlier ships with an empty loginhash_pwd field in its default configuration, so the console accepts a crafted login request with…EPSS 66%analysed9.8CVE-2023-44091Artica pandora fms sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. This u…EPSS 0.45%9.8CVE-2023-4677Artica pandora fms improper authentication vulnerabilityCron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs…EPSS 0.49%9.8CVE-2023-41790Artica pandora fms uncontrolled search path element vulnerabilityUncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File Search Paths. This vulnerabili…EPSS 0.57%9.8CVE-2021-32098Artica pandora fms deserialization of untrusted data vulnerabilityArtica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.EPSS 2.5%9.8CVE-2020-26518Artica pandora fms sql injection vulnerabilityArtica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/include/chart_generator.php s…EPSS 2.1%9.8CVE-2018-11221Artica pandora fms unrestricted file upload vulnerabilityUnauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an attacker to upload an arbitrary plugin via include/ajax/up…EPSS 5.6%9.4CVE-2024-35307Artica pandora fms argument injection vulnerabilityArgument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to execute arbitrary code on the …EPSS 0.91%

Source: NIST National Vulnerability Database (record CVE-2021-32099), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.