Back to Database
Status published
High
CVE-2025-4678
Remote Code Execution leads to Command Injection
Vulnerability Description
Improper Neutralization of Special Elements in the chromium_path variable may allow OS command injection. This issue affects Pandora ITSM 5.0.105.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-4678
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- h00die-gr3y (h00die.gr3y@gmail.com)
More from Pandora FMS
View All →CVE-2025-5306
Command Injection in Netflow path
High
7
CVE-2025-4653
Remote Code Execution leads to Command Injection
High
7
CVE-2024-9987
SQL Injection in CSV Module Data Collection
High
8.6
CVE-2024-35308
Post-auth Arbitrary File Read in the Server Plugins Section
High
8.3
CVE-2024-35307
Argument Injection Leading to Remote Code Execution in Realtime Graph Extension
Critical
9.4
Affected Vendor
Pandora FMS
View all reports →Affected Software
Pandora ITSM
Vulnerable Versions:
5.0.105
Timeline
Official Publish:
June 10th, 2025
Last Modified:
June 10th, 2025
Added to House:
July 22nd, 2026