Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

George-Karo

#51474de 53,625
4.3CVSS total
Vulnerabilidades · 1
PT-2019-5225
4.3
2019-09-23
Cacti · Cacti · CVE-2019-16723
**Name of the Vulnerable Software and Affected Versions** Cacti versions prior to 1.2.7 **Description** The issue is related to an authorization check error in the local graph id function of the Cacti server monitoring system. This allows a remote attacker to potentially access confidential data by bypassing authorization checks for viewing graphs. The exploitation involves making a direct request to the graph json.php endpoint with a modified `local graph id` parameter. **Recommendations** For Cacti versions prior to 1.2.7, update to version 1.2.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the graph json.php endpoint to minimize the risk of exploitation.