CVE-2023-39365SQL Injection in Cacti

CWE-89SQL Injection3 documents3 sources
Severity
6.3MEDIUMNVD
EPSS
0.2%
top 61.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 5

Description

Cacti is an open source operational monitoring and fault management framework. Issues with Cacti Regular Expression validation combined with the external links feature can lead to limited SQL Injections and subsequent data leakage. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 2.8 | Impact: 3.4

Affected Packages3 packages

NVDcacti/cacti< 1.2.25
debiandebian/cacti< cacti 1.2.24+ds1-1+deb12u1 (bookworm)
Debiancacti/cacti< 1.2.16+ds1-2+deb11u2+3

Also affects: Fedora 37, 38

🔴Vulnerability Details

1
OSV
CVE-2023-39365: Cacti is an open source operational monitoring and fault management framework2023-09-05

📋Vendor Advisories

1
Debian
CVE-2023-39365: cacti - Cacti is an open source operational monitoring and fault management framework. I...2023