CVE-2023-39361: Unauthenticated SQL Injection in graph_view.php in Cacti
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graphview.php. Since guest users can access graphview.php without authentication by default, if guest users are being utilized in an enabled state, there could be the potential for significant damage. Attackers may exploit this vulnerability, and there may be possibilities for actions such as the usurpation of administrative privileges or remote code execution. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-39361?
CVE-2023-39361 is a vulnerability discovered in Cacti, an open source operational monitoring and fault management framework, that allows for SQL injection in graph_view.php.
How severe is CVE-2023-39361?
CVE-2023-39361 has a severity rating of 9.8, which is classified as critical.
Which version of Cacti is affected by CVE-2023-39361?
Cacti version 1.2.24 is affected by CVE-2023-39361.
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-39361?
The CWE ID for CVE-2023-39361 is CWE-89.
How can I fix the CVE-2023-39361 vulnerability?
To fix the CVE-2023-39361 vulnerability, it is recommended to update Cacti to a version that includes the necessary security patches and to apply any provided fixes or workarounds.