CVE-2019-17357
15Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackepss 35%
probabilidade de exploração
35%top 2% das CVEs
exploração observada
nãonenhuma fonte reporta
Cacti through 1.2.7 is affected by a graphs.php?template_id= SQL injection vulnerability affecting how template identifiers are handled when a string and id composite value are used to identify the template type and id. An authenticated attacker can exploit this to extract data from the database, or an unauthenticated remote attacker could exploit this via Cross-Site Request Forgery.
Produtos afetados
n/a · n/aReferências
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-03/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-04/msg00042.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-04/msg00048.htmlhttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=947374https://github.com/Cacti/cacti/issues/3025https://security.gentoo.org/glsa/202003-40https://www.darkmatter.ae/xen1thlabs/