CVE-2023-39361
Unauthenticated SQL Injection in graph_view.php in Cacti
- Published
- Sep 5, 2023
- Updated
- Feb 13, 2025
- Assigning CNA
- GitHub_M
- Evidence observed
- Aug 7, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.8%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an enabled state, there could be the potential for significant damage. Attackers may exploit this vulnerability, and there may be possibilities for actions such as the usurpation of administrative privileges or remote code execution. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Sources
3Proof-of-concept exploit for CVE-2023-39361, a SQL injection in Cacti graph_view.php leading to data exfiltration and potential RCE.
- CVE-2023-39361Research
Step-by-step analysis and lab setup for CVE-2023-39361, an unauthenticated SQL injection in Cacti v1.2.24, with exploitation and mitigation walkthrough.
- cacti-cve-2023-39361Exploit
Exploit for CVE-2023-39361 in Cacti, a network graphing solution, demonstrating SQL injection vulnerability for educational and security testing purposes.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.