CVE-2014-2327Cross-Site Request Forgery in Cacti

Severity
6.8MEDIUMNVD
EPSS
0.4%
top 37.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 23
Latest updateMay 14

Description

Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack the authentication of users for unspecified commands, as demonstrated by requests that (1) modify binary files, (2) modify configurations, or (3) add arbitrary users.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages4 packages

debiandebian/cacti< cacti 0.8.8b+dfsg-6 (bookworm)
Debiancacti/cacti< 0.8.8b+dfsg-6+3
NVDcacti/cacti0.8.70.8.7g+1
NVDopensuse/opensuse13.1, 13.2+1

Also affects: Debian Linux 7.0, 8.0

🔴Vulnerability Details

2
GHSA
GHSA-w6fq-c949-4cc3: Cross-site request forgery (CSRF) vulnerability in Cacti 02022-05-14
OSV
CVE-2014-2327: Cross-site request forgery (CSRF) vulnerability in Cacti 02014-04-23

📋Vendor Advisories

1
Debian
CVE-2014-2327: cacti - Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and ear...2014

💬Community

4
Bugzilla
CVE-2015-2327 pcre: infinite recursion compiling pattern with zero-repeated groups that include recursive back reference (8.36/19)2015-11-25
Bugzilla
CVE-2014-2327 CVE-2014-2326 CVE-2014-2328 cacti: multiple flaws reported by Deutsche Telekom [fedora-all]2014-04-01
Bugzilla
CVE-2014-2327 CVE-2014-2326 CVE-2014-2328 cacti: multiple flaws reported by Deutsche Telekom [epel-all]2014-04-01
Bugzilla
CVE-2014-2326 CVE-2014-2327 CVE-2014-2328 cacti: multiple flaws reported by Deutsche Telekom2014-03-28