Authenticated SQL injection vulnerability in reports_user.php in Cacti
CVE-2023-39358

8.8HIGH

Key Information:

Vendor

Cacti

Status
Vendor
CVE Published:
5 September 2023

What is CVE-2023-39358?

An authentication-bypassed SQL injection vulnerability exists in the Cacti monitoring framework, specifically within the reports_user.php file. This flaw allows authenticated users to manipulate the tree_id parameter during calls to reports_get_branch_select without adequate sanitization, enabling malicious actors to escalate their privileges and potentially execute arbitrary code on the server. The issue has been rectified in the newly released version 1.2.25. Users are strongly encouraged to upgrade to mitigate risks as there are currently no alternative workarounds available.

Affected Version(s)

cacti < 1.2.25

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.