PT-2023-8200 · Cacti+1 · Cacti+1

Umbrassador

+1

·

Published

2023-09-05

·

Updated

2025-01-24

·

CVE-2023-49088

CVSS v2.0

7.7

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Cacti versions prior to 1.2.25
Description The issue exists due to inadequate protection of the web page structure, allowing a remote attacker to execute arbitrary code. This can be achieved through a cross-site scripting attack when a victim user hovers over a malicious data source path in the data debug.php file. The attacker must have specific permissions, including General Administration>Sites/Devices/Data, to perform the attack. The victim can be any account with permissions to view the http://<HOST>/cacti/data debug.php endpoint.
Recommendations For versions prior to 1.2.25, consider restricting access to the data debug.php file and limiting permissions to General Administration>Sites/Devices/Data to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2024-7120
ALT-PU-2025-1813
BDU:2024-00192
CVE-2023-49088
DLA-3765-1
DSA-5646-1
GHSA-HRG9-QQQX-WC4H
GHSA-Q7G7-GCF6-WH4X
OPENSUSE-SU-2024:0031-1
OPENSUSE-SU-2024:13533-1

Affected Products

Alt Linux
Cacti