CVE detail
CVE-2023-37543 — CVE-2023-37543
Published 2023-08-10 · Modified 2026-06-17 · Vendor cacti · Product cacti · Source nvd
HIGH
severity
CVSS-derived band
0.0086
EPSS probability
exploitation probability, 30d
55.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Cacti before 1.2.6 allows IDOR (Insecure Direct Object Reference) for accessing any graph via a modified local_graph_id parameter to graph_xport.php. This is a different vulnerability than CVE-2019-16723.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References