CVE-2023-37543

Source
https://cve.org/CVERecord?id=CVE-2023-37543
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-37543.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-37543
Aliases
  • GHSA-4x82-8w8m-w8hj
Downstream
Published
2023-08-10T00:00:00Z
Modified
2026-05-28T03:53:47.633544980Z
Summary
[none]
Details

Cacti before 1.2.6 allows IDOR (Insecure Direct Object Reference) for accessing any graph via a modified localgraphid parameter to graph_xport.php. This is a different vulnerability than CVE-2019-16723.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/37xxx/CVE-2023-37543.json",
    "cna_assigner": "mitre"
}
References

Affected packages

Git / github.com/cacti/cacti

Affected ranges

Type
GIT
Repo
https://github.com/cacti/cacti
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

release/1.*
release/1.0.0
release/1.0.1
release/1.0.2
release/1.0.3
release/1.0.4
release/1.0.5
release/1.0.6
release/1.1.0
release/1.1.1
release/1.1.11
release/1.1.12
release/1.1.13
release/1.1.14
release/1.1.15
release/1.1.16
release/1.1.17
release/1.1.18
release/1.1.19
release/1.1.2
release/1.1.20
release/1.1.21
release/1.1.22
release/1.1.23
release/1.1.24
release/1.1.25
release/1.1.26
release/1.1.27
release/1.1.28
release/1.1.29
release/1.1.3
release/1.1.30
release/1.1.31
release/1.1.32
release/1.1.33
release/1.1.34
release/1.1.35
release/1.1.36
release/1.1.37
release/1.1.38
release/1.1.4
release/1.1.5
release/1.1.6
release/1.1.7
release/1.1.8
release/1.2.0
release/1.2.1
release/1.2.2
release/1.2.3
release/1.2.4
release/1.2.5

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-37543.json"