CVE-2023-39357: A Defect in sql_save() Causes Multiple SQL Injection Vulnerabilities in Cacti
Cacti is an open source operational monitoring and fault management framework. A defect in the sqlsave function was discovered. When the column type is numeric, the sqlsave function directly utilizes user input. Many files and functions calling the sqlsave function do not perform prior validation of user input, leading to the existence of multiple SQL injection vulnerabilities in Cacti. This allows authenticated users to exploit these SQL injection vulnerabilities to perform privilege escalation and remote code execution. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-39357?
CVE-2023-39357 is a vulnerability in the Cacti open source operational monitoring and fault management framework.
How severe is CVE-2023-39357?
CVE-2023-39357 has a severity rating of 8.8, which is considered high.
What is the affected software by CVE-2023-39357?
The affected software by CVE-2023-39357 is Cacti version 1.2.24.
What is the root cause of CVE-2023-39357?
The root cause of CVE-2023-39357 is a defect in the sql_save function in Cacti.
Are there any references for CVE-2023-39357?
Yes, you can find more information about CVE-2023-39357 at the following link: [GitHub Advisory](https://github.com/Cacti/cacti/security/advisories/GHSA-6jhp-mgqg-fhqg).