A Defect in sql_save() Causes Multiple SQL Injection Vulnerabilities in Cacti
CVE-2023-39357

8.8HIGH

Key Information:

Vendor

Cacti

Status
Vendor
CVE Published:
5 September 2023

What is CVE-2023-39357?

Cacti, an open source operational monitoring and fault management framework, contains a vulnerability within its sql_save function, which handles user input without proper validation. This defect can lead to SQL injection attacks, allowing authenticated users to execute malicious queries and potentially escalate their privileges or execute code remotely. As the vulnerability affects multiple files sharing the sql_save function, users are strongly advised to upgrade to version 1.2.25 to secure their systems against these risks. No workarounds are available to mitigate the vulnerabilities.

Affected Version(s)

cacti < 1.2.25

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
The Cyber Security Vulnerability Database.