CVE-2023-39361 is a critical SQL injection vulnerability affecting Cacti versions prior to 1.2.25. This flaw, found in graph_view.php, allows unauthenticated guest users to execute arbitrary SQL queries, potentially leading to administrative privilege escalation or remote code execution. With a CVSS score of 9.8 (CRITICAL) and an EPSS score of 0.92278, this vulnerability is easily exploitable over the network with low attack complexity and no user interaction required. While not yet listed in CISA's KEV catalog, public exploit templates exist (e.g., Nuclei), and it has garnered significant community discussion, indicating a high likelihood of future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2.24CPE matchmatch criteria | cpe:2.3:a:cacti:cacti:1.2.24:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.