Description
Pandora ITSM is a platform for Service Management & Support including a Helpdesk for support and customer service teams, aligned with ITIL processes. This module exploits a command injection vulnerability in the `name` backup setting at the application setup page of Pandora ITSM. This can be triggered by generating a backup with a malicious payload injected at the `name` parameter. You need to have admin access at the Pandora ITSM Web application in order to execute this RCE. This access can be achieved by knowing the admin credentials to access the web application or leveraging a default password vulnerability in Pandora ITSM that allows an attacker to access the Pandora FMS ITSM database, create a new admin user and gain administrative access to the Pandora ITSM Web application. This attack can be remotely executed over the WAN as long as the MySQL services are exposed to the outside world. This issue affects all ITSM Enterprise editions up to `5.0.105` and is patched at `5.0.106`.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/linux/http/pandora/itsm_auth_rce_cve_2025_4653msf undefined(itsm_auth_rce_cve_2025_4653) > show actions ...actions...msf undefined(itsm_auth_rce_cve_2025_4653) > set ACTION < action-name >msf undefined(itsm_auth_rce_cve_2025_4653) > show options ...show and set options...msf undefined(itsm_auth_rce_cve_2025_4653) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub