CVE-2023-39361
9.8
CRITICAL
CVSS 3.1
EPSS 87.6%
描述
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an enabled state, there could be the potential for significant damage. Attackers may exploit this vulnerability, and there may be possibilities for actions such as the usurpation of administrative privileges or remote code execution. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.
如何修補 CVE-2023-39361
要修補 CVE-2023-39361,請將受影響套件升級到下列已修補版本。
- —升級至 1.2.16+ds1-2+deb11u2 或更新版本
CVE-2023-39361 正在被利用嗎?
可能 — EPSS 為 87.6%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- from 0, < 1.2.16+ds1-2+deb11u2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |