SQL injection in Cacti - CVE-2023-39361
Published: September 5, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data within the grow_right_pane_tree() function in graph_view.php. A remote non-authenticated attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.
Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.
Affected software
Debian Linux
Fedora
Ubuntu
cacti (Ubuntu package)
cacti (Debian package)
cacti
cacti-spine
How to mitigate CVE-2023-39361
cacti (Ubuntu package) - update to Ubuntu Pro
cacti (Debian package) - addressed in versions 1.2.16+ds1-2+deb11u2, 1.2.24+ds1-1+deb12u1
cacti - addressed in versions 1.2.25-1.el7, 1.2.25-1.el8, 1.2.25-1.el9, 1.2.25-1.fc37, 1.2.25-1.fc38, 1.2.25-1.fc39
cacti-spine - addressed in versions 1.2.25-1.el7, 1.2.25-1.el8, 1.2.25-1.el9, 1.2.25-1.fc37, 1.2.25-1.fc38, 1.2.25-1.fc39
External References
Related Security Bulletins
- Multiple vulnerabilities in Cacti
- Fedora 38 update for cacti, cacti-spine
- Fedora 37 update for cacti, cacti-spine
- Fedora 39 update for cacti, cacti-spine
- Fedora EPEL 7 update for cacti, cacti-spine
- Fedora EPEL 9 update for cacti, cacti-spine
- Fedora EPEL 8 update for cacti, cacti-spine
- Debian update for cacti
- Ubuntu update for cacti