PT-2023-4942 · Cacti+2 · Cacti+2

K0Pak4

·

Published

2023-09-05

·

Updated

2025-01-24

·

CVE-2023-30534

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cacti versions 1.2.24
Description The issue is related to insecure deserialization in Cacti, specifically within the host new graphs save function in graphs new.php. This is due to the use of the unserialize function without sanitizing user input. Although a viable gadget chain exists in Cacti's vendor directory, the necessary gadgets are not included, making the insecure deserializations not exploitable. It is estimated that about 16,674 results are potentially affected. The issue has been addressed in version 1.2.25.
Recommendations For Cacti version 1.2.24, upgrade to version 1.2.25 to resolve the issue. As a temporary workaround, consider restricting access to the graphs new.php file or disabling the host new graphs save function until the upgrade can be applied. Avoid using the unserialize function without proper sanitization of user input.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-7619
ALT-PU-2023-7621
ALT-PU-2024-7120
ALT-PU-2025-1813
BDU:2023-05455
CVE-2023-30534
GHSA-77RF-774J-6H3P
OPENSUSE-SU-2023:0275-1
OPENSUSE-SU-2024:13203-1

Affected Products

Alt Linux
Cacti
Debian