CVE-2023-37543
CVSS V2 None
CVSS V3 None
Description
Cacti before 1.2.6 allows IDOR (Insecure Direct Object Reference) for accessing any graph via a modified local_graph_id parameter to graph_xport.php. This is a different vulnerability than CVE-2019-16723.
Overview
- CVE ID
- CVE-2023-37543
- Assigner
- cve@mitre.org
- Vulnerability Status
- Analyzed
- Published Version
- 2023-08-10T15:15:09
- Last Modified Date
- 2023-08-17T21:18:32
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:* | 1 | OR | 1.2.6 |
References
Reference URL | Reference Tags |
---|---|
https://github.com/Cacti/cacti/security/advisories/GHSA-4x82-8w8m-w8hj | Broken Link |
https://medium.com/@hussainfathy99/exciting-news-my-first-cve-discovery-cve-2023-37543-idor-vulnerability-in-cacti-bbb6c386afed | Exploit Third Party Advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-37543 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-37543 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-09-06 03:29:41 | Added to TrackCVE | |||
2023-09-06 03:29:44 | Weakness Enumeration | new |