Vulnerability CVE-2019-16723: Information

Description

In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_json.php request with a modified local_graph_id parameter.

Severity: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Published: Sept. 23, 2019
Modified: Nov. 7, 2023
Error type identifier: CWE-639

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
cactisisyphus1.2.10-alt11.2.26-alt1ALT-PU-2020-1488-1247881Fixed
cactip101.2.10-alt11.2.26-alt1ALT-PU-2020-1488-1247881Fixed
cactip91.2.15-alt31.2.15-alt3ALT-PU-2020-3430-1262340Fixed
cactic10f11.2.10-alt11.2.26-alt1ALT-PU-2020-1488-1247881Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*
      End including
      1.2.6