peter bassill · operator
$ cve CVE-2023-39361 JSON

CVE-2023-39361

9.8
CRITICAL · CVSS 3.1 · EPSS 88.8% (pctl 100)

Patch early

EPSS 88.8% — above the 10% action threshold.

Description

Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an enabled state, there could be the potential for significant damage. Attackers may exploit this vulnerability, and there may be possibilities for actions such as the usurpation of administrative privileges or remote code execution. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS88.79% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploitnone known
Published2023-09-05
Last modified2026-06-17

Affected (2)

VendorProduct
cacticacti
fedoraprojectfedora

References

→ the Explorer  ·  watch your stack  ·  NVD