S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-39361 Scanner

Detects 'SQL Injection (SQLi)' vulnerability in Cacti affects v. before 1.2.25.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-39361
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an enabled state, there could be the potential for significant damage. Attackers may exploit this vulnerability, and there may be possibilities for actions such as the usurpation of administrative privileges or remote code execution. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
cactiby Cacti
< 1.2.25
Updated Aug 22, 2026View on NVD →
Detail

Cacti is an open-source framework used for operational monitoring and fault management. It is designed for network administrators or IT professionals to analyze and visualize the performance of their networks by using various charting capabilities. This product is widely used because it not only monitors network devices but also various other internal services and software. The easy-to-use interface and open-source nature of this product make it highly customizable and useful.

CVE-2023-39361 is a SQL injection vulnerability found in Cacti's graph_view.php. This vulnerability is highly critical as it is readily exploitable by any guest user without authentication. A SQL injection attack allows an attacker to add, manipulate, or delete data in the database. This could result in the data breach of sensitive information or compromise of the system's integrity. Attackers could also gain unauthorized access to administrative privileges and execute arbitrary code remotely on the server.

The exploitation of this vulnerability can lead to significant damage to the network system. It could result in the compromise of confidential information, system downtime, or even the complete takeover of the network by malicious actors. The exploitation of this vulnerability carries a high risk that could lead to significant financial and reputational losses for businesses.

By using the pro features of the s4e.io platform, readers of this article can quickly and easily learn about vulnerabilities in their digital assets. The platform provides a comprehensive report on all vulnerabilities detected in the system by using the latest scanning techniques. This platform gives users a powerful tool to monitor their digital assets proactively, detect vulnerabilities, and prevent potential attacks from malicious actors.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users are advised to upgrade to version 1.2.25. Additionally, the following precautions can be taken:

  • Implement network segmentation to reduce the attack surface
  • Disable guest user access by default
  • Restrict web-server permissions
  • Harden the database by using strong passwords, limiting permissions, and avoiding default accounts and ports
  • Regularly monitor network activity and logs to detect suspicious behavior

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.