Cacti through 1.2.7 is affected by a graphs.php?template_id= SQL injection vulnerability affecting how template identifiers are handled when a string and id composite value are used to identify the template type and id. An authenticated attacker can exploit this to extract data from the database, or an unauthenticated remote attacker could exploit this via Cross-Site Request Forgery.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade cacti | Jul 30, 2024 | Jan 21, 2020 |
| Freebsd | — | Upgrade cacti | Jan 7, 2020 | Jan 6, 2020 |
| Gentoo Linux | — | Upgrade net-analyzer/cacti. | Mar 20, 2020 | Jan 21, 2020 |
| Suse | — | Upgrade cactiUpgrade cacti-spine | Mar 3, 2020 | Oct 12, 2019 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jan 21, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub