Cacti through 1.2.7 is affected by a graphs.php?template_id= SQL injection vulnerability affecting how template identifiers are handled when a string and id composite value are used to identify the template type and id. An authenticated attacker can exploit this to extract data from the database, or an unauthenticated remote attacker could exploit this via Cross-Site Request Forgery.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DSA-4604-1 | cacti security update |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T01:40:15.202Z
Reserved: 2019-10-08T00:00:00
Link: CVE-2019-17357

No data.

Status : Modified
Published: 2020-01-21T19:15:13.067
Modified: 2024-11-21T04:32:09.900
Link: CVE-2019-17357

No data.

No data.