CVE-2019-17358
Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and control actions taken by Cacti or potentially cause memory corruption in the PHP module.
- Cacti
- ≤ 1.2.7
- Fix
- Available
- CVSS 3.1
- 8.1 HIGH
- EPSS
- 3.0% (86th percentile)
- Weakness
- CWE-502, CWE-787
- NVD status
- Modified
- Published
- 2019-12-12
CVE-2019-17358 at NVD
No indexed exploits for CVE-2019-17358 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2019-17358 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.