CVE-2023-39365
Cacti is an open source operational monitoring and fault management framework. Issues with Cacti Regular Expression validation combined with the external links feature can lead to limited SQL Injections and subsequent data leakage. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.
- Cacti
- < 1.2.25
- Fix
- Available
- CVSS 3.1
- 6.3 MEDIUM
- EPSS
- 0.9% (55th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2023-09-05
CVE-2023-39365 at NVD
No indexed exploits for CVE-2023-39365 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2023-39365 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.