Pandora ITSM OS Command Injection Vulnerability

Vulnerability

A vulnerability allowing OS command injection has been identified in Pandora ITSM version 5.0.105. This issue arises from improper neutralization of special elements in the 'chromium_path' variable, which may be exploited to inject and execute arbitrary commands on the operating system.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of OS commands, potentially allowing an attacker to manipulate the system or application environment.

Added: Jun 10, 2025, 4:25 PM
Updated: Jun 10, 2025, 4:25 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.8
remediation
0.0
relevance
0.2
threat
0.0
urgency
1.4
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.