USN-6720-1: Cacti vulnerability
Published Apr 2, 2024
·Updated
Kentaro Kawane discovered that Cacti incorrectly handled user provided input sent through request parameters to the graphview.php script. A remote authenticated attacker could use this issue to perform SQL injection attacks.
Affected Software
2 affected componentsFixes available
All of the following
ubuntu/cacti<1.2.19+ds1-2ubuntu1+esm1
1.2.19+ds1-2ubuntu1+esm1
Ubuntu Ubuntu=22.04
Event History
Apr 2, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-6720-1?
The severity of USN-6720-1 is classified as high, indicating a significant risk of SQL injection vulnerabilities.
2
How do I fix USN-6720-1?
To fix USN-6720-1, upgrade the Cacti package to version 1.2.19+ds1-2ubuntu1+esm1 or later.
3
Who is affected by USN-6720-1?
USN-6720-1 affects users of the Cacti package on Ubuntu 22.04.
4
What kind of attack is possible with USN-6720-1?
USN-6720-1 allows remote authenticated attackers to perform SQL injection attacks via specially crafted request parameters.
5
When was USN-6720-1 published?
USN-6720-1 was published to address vulnerabilities discovered in Cacti.