First published: Thu Aug 10 2023(Updated: )
Cacti before 1.2.6 allows IDOR (Insecure Direct Object Reference) for accessing any graph via a modified local_graph_id parameter to graph_xport.php. This is a different vulnerability than CVE-2019-16723.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cacti Cacti | <1.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-37543 is high with a CVSS score of 7.5.
CVE-2023-37543 is an IDOR (Insecure Direct Object Reference) vulnerability in Cacti before version 1.2.6 that allows unauthorized access to any graph.
An attacker can exploit CVE-2023-37543 by modifying the local_graph_id parameter in graph_xport.php to access any graph.
Yes, CVE-2023-37543 is a different vulnerability than CVE-2019-16723.
To fix CVE-2023-37543, upgrade to Cacti version 1.2.6 or later.