Unsanitized concatenation of the module parameter in the Grafana datasource endpoint allows authenticated blind SQL injection. Affects Pandora FMS from 777 onwards.
Advisories
No advisories yet.
Fixes
Solution
Fixed v800.6 and v805
Workaround
No workaround given by the vendor.
References
History
Thu, 01 Oct 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pandora Fms
Pandora Fms pandora Fms |
|
| Vendors & Products |
Pandora Fms
Pandora Fms pandora Fms |
Thu, 01 Oct 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unsanitized concatenation of the module parameter in the Grafana datasource endpoint allows authenticated blind SQL injection. Affects Pandora FMS from 777 onwards. | |
| Title | SQL Injection in Grafana Integration Endpoint (query.php) | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: PandoraFMS
Published:
Updated: 2026-10-01T09:30:48.977Z
Reserved: 2026-08-18T07:12:08.965Z
Link: CVE-2026-75786
No data.
Status : Deferred
Published: 2026-10-01T10:17:16.530
Modified: 2026-10-01T12:45:05.900
Link: CVE-2026-75786
No data.
OpenCVE Enrichment
Updated: 2026-10-01T10:45:07Z
Weaknesses