CVE-2019-16723 PUBLISHED

In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_json.php request with a modified local_graph_id parameter.

EPSS 0.27% · 50.1th percentile

Risk Scores

EPSS Score
0.27%
50.1th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTScacti0, 0.8.8b+dfsg-3, 0.8.8b+dfsg-5
Ubuntu:Pro:18.04:LTScacti0, 1.1.18+ds1-1, 1.1.27+ds1-2

Timeline

References

Open in Interactive Console →