PT-2023-5425 · Cacti+1 · Cacti+1
X4Vak
·
Published
2023-09-05
·
Updated
2025-01-24
·
CVE-2023-39358
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cacti versions prior to 1.2.25
Description
An authenticated SQL injection issue allows authenticated users to perform privilege escalation and remote code execution. The issue resides in the
reports user.php file, specifically in the ajax get branches function where the tree id parameter is passed to the reports get branch select function without validation.Recommendations
For versions prior to 1.2.25, upgrade to version 1.2.25 or later to address the issue. As a temporary workaround, consider restricting access to the
reports user.php file and the ajax get branches function until a patch is applied. Avoid using the tree id parameter in the affected function until the issue is resolved.Exploit
Fix
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Cacti