CVE-2023-49086
- EPSS 0.95%
- Veröffentlicht 22.12.2023 00:15:34
- Zuletzt bearbeitet 04.11.2025 19:16:08
Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). A vulnerability in versions prior to 1.2.27 bypasses an earlier fix for CVE-2023-39360, therefore leading to a DOM XSS attack. Exp...
CVE-2023-49084
- EPSS 88.34%
- Veröffentlicht 21.12.2023 23:15:09
- Zuletzt bearbeitet 21.11.2024 08:32:47
Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL Injection and insufficient processing of the include file path, it is possible to execute arbitrary c...
CVE-2023-46490
- EPSS 0.21%
- Veröffentlicht 27.10.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 08:28:35
SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain sensitive information via the form_actions() function in the managers.php function.
CVE-2023-39511
- EPSS 0.51%
- Veröffentlicht 06.09.2023 18:15:08
- Zuletzt bearbeitet 10.04.2025 20:43:41
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. Thes...
CVE-2023-39365
- EPSS 0.17%
- Veröffentlicht 05.09.2023 22:15:09
- Zuletzt bearbeitet 13.02.2025 17:16:52
Cacti is an open source operational monitoring and fault management framework. Issues with Cacti Regular Expression validation combined with the external links feature can lead to limited SQL Injections and subsequent data leakage. This issue has bee...
CVE-2023-39516
- EPSS 0.26%
- Veröffentlicht 05.09.2023 22:15:09
- Zuletzt bearbeitet 10.04.2025 20:51:38
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. Thes...
CVE-2023-30534
- EPSS 41.97%
- Veröffentlicht 05.09.2023 22:15:08
- Zuletzt bearbeitet 11.04.2025 14:48:45
Cacti is an open source operational monitoring and fault management framework. There are two instances of insecure deserialization in Cacti version 1.2.24. While a viable gadget chain exists in Cacti’s vendor directory (phpseclib), the necessary gadg...
CVE-2023-31132
- EPSS 0.12%
- Veröffentlicht 05.09.2023 22:15:08
- Zuletzt bearbeitet 11.04.2025 14:17:51
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a privilege escalation vulnerability. A low-privileged OS user with access to a Windows host where Cacti is installed can create arbitrary...
CVE-2023-39357
- EPSS 3.25%
- Veröffentlicht 05.09.2023 22:15:08
- Zuletzt bearbeitet 21.11.2024 08:15:13
Cacti is an open source operational monitoring and fault management framework. A defect in the sql_save function was discovered. When the column type is numeric, the sql_save function directly utilizes user input. Many files and functions calling the...
CVE-2023-39358
- EPSS 3.99%
- Veröffentlicht 05.09.2023 22:15:08
- Zuletzt bearbeitet 21.11.2024 08:15:13
Cacti is an open source operational monitoring and fault management framework. An authenticated SQL injection vulnerability was discovered which allows authenticated users to perform privilege escalation and remote code execution. The vulnerability r...