Authenticated SQL injection vulnerability in reports_user.php in Cacti
CVE-2023-39358
What is CVE-2023-39358?
An authentication-bypassed SQL injection vulnerability exists in the Cacti monitoring framework, specifically within the reports_user.php file. This flaw allows authenticated users to manipulate the tree_id parameter during calls to reports_get_branch_select without adequate sanitization, enabling malicious actors to escalate their privileges and potentially execute arbitrary code on the server. The issue has been rectified in the newly released version 1.2.25. Users are strongly encouraged to upgrade to mitigate risks as there are currently no alternative workarounds available.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
cacti < 1.2.25
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
