Description
Unsanitized concatenation of the module parameter in the Grafana datasource endpoint allows authenticated blind SQL injection. Affects Pandora FMS from 777 onwards.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Fixed v800.6 and v805
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 01 Oct 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unsanitized concatenation of the module parameter in the Grafana datasource endpoint allows authenticated blind SQL injection. Affects Pandora FMS from 777 onwards. | |
| Title | SQL Injection in Grafana Integration Endpoint (query.php) | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: PandoraFMS
Published:
Updated: 2026-10-01T09:30:48.977Z
Reserved: 2026-08-18T07:12:08.965Z
Link: CVE-2026-75786
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses