Several SQL injection vulnerabilities have been discovered in Cacti. Specially crafted input can be used by an attacker in the rra_id value of the graph.php script to execute arbitrary SQL commands on the database (CVE-2015-8369).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2016-0025.json"