PT-2023-4991 · Cacti+1 · Cacti+1

X4Vak

·

Published

2023-09-05

·

Updated

2025-01-24

·

CVE-2023-39359

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cacti versions prior to 1.2.25
Description An authenticated SQL injection issue was discovered in Cacti, an open source operational monitoring and fault management framework. This issue allows authenticated users to perform privilege escalation and remote code execution. The vulnerability is located in the graphs.php file and is related to the ajax hosts and ajax hosts noany functions. When the site id parameter is greater than 0, it is directly reflected in the WHERE clause of the SQL statement, creating an SQL injection vulnerability.
Recommendations For versions prior to 1.2.25, upgrade to version 1.2.25 or later to address the issue. As a temporary workaround, consider restricting access to the graphs.php file or disabling the ajax hosts and ajax hosts noany functions until a patch is applied. Avoid using the site id parameter in the affected API endpoints until the issue is resolved.

Exploit

Fix

RCE

SQL injection

Weakness Enumeration

Related Identifiers

ALT-PU-2023-7619
ALT-PU-2023-7621
ALT-PU-2024-7120
ALT-PU-2025-1813
BDU:2023-05530
CVE-2023-39359
DSA-5550-1
GHSA-Q4WH-3F9W-836H
OPENSUSE-SU-2023:0275-1
OPENSUSE-SU-2024:13203-1

Affected Products

Alt Linux
Cacti