Description
Cacti through 1.2.7 is affected by a graphs.php?template_id= SQL injection vulnerability affecting how template identifiers are handled when a string and id composite value are used to identify the template type and id. An authenticated attacker can exploit this to extract data from the database, or an unauthenticated remote attacker could exploit this via Cross-Site Request Forgery.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4604-1 | cacti security update |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T01:40:15.202Z
Reserved: 2019-10-08T00:00:00.000Z
Link: CVE-2019-17357
No data.
Status : Modified
Published: 2020-01-21T19:15:13.067
Modified: 2024-11-21T04:32:09.900
Link: CVE-2019-17357
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA