CVE-2023-39361
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view...
Affects 2 products across 2 vendors.
Attacker inserts SQL commands into application queries through user-controlled input, allowing unauthorized database access.
Show all 6
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A critical SQL injection vulnerability exists in Cacti's graph_view.php, affecting unauthenticated guest users. This could lead to unauthorized data access and manipulation.
BSID: BS-2023-GLOBAL-262240-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2023-39361?
What is the CVSS score for CVE-2023-39361?
Is CVE-2023-39361 actively exploited?
How do I remediate CVE-2023-39361?
What systems are affected by CVE-2023-39361?
| CVE ID | CVE-2023-39361 |
|---|---|
| BSID | BS-2023-GLOBAL-262240-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2023-09-05 |
| Last Modified | 2024-11-21 |
| ICS Relevance | 0% |
| Weakness (CWE) | |
| Source | NVD |
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an enabled state, there could be the potential for significant damage. Attackers may exploit this vulnerability, and there may be possibilities for actions such as the usurpation of administrative privileges or remote code execution. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Source: NIST NVD / MITRE CVE Database
The vulnerability is located in the graph_view.php file, which can be accessed by guest users without authentication. An attacker can exploit this to perform SQL injection attacks, potentially compromising the database.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Cacti | Cacti | — |
| Fedoraproject | Fedora | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 40ec6a4814496f2d583fce7a3305b309029f53b2079516ffde30b99a05a0e1e0ae76412c2b7500328a754e98ebe2fd406a41e75a33b548179e2bddfcacbcc8d6 |
Critical Severity - Know Your Exposure
A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →