PT-2019-5225 · Cacti+2 · Cacti+2

George-Karo

·

Publicado

2019-09-23

·

Atualizado

2025-01-24

·

CVE-2019-16723

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cacti versions prior to 1.2.7
Description The issue is related to an authorization check error in the local graph id function of the Cacti server monitoring system. This allows a remote attacker to potentially access confidential data by bypassing authorization checks for viewing graphs. The exploitation involves making a direct request to the graph json.php endpoint with a modified local graph id parameter.
Recommendations For Cacti versions prior to 1.2.7, update to version 1.2.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the graph json.php endpoint to minimize the risk of exploitation.

Exploit

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2020-1488
ALT-PU-2020-3430
ALT-PU-2025-1813
BDU:2020-01954
CVE-2019-16723
DSA-4604-1
OPENSUSE-SU-2020:0272-1
OPENSUSE-SU-2020:0284-1
OPENSUSE-SU-2020:0558-1
OPENSUSE-SU-2020:0565-1
OPENSUSE-SU-2020_0272-1
OPENSUSE-SU-2020_0558-1
OPENSUSE-SU-2024:10670-1

Produtos afetados

Alt Linux
Cacti
Suse