diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 7d8ca6b97fc1..32406dfe14e1 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -58,6 +58,34 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + cacti -- Authenticated users may bypass authorization checks + + + cacti + 1.2.7 + + + + +

The cacti developers reports:

+
+

In Cacti through 1.2.6, authenticated users may bypass authorization checks + (for viewing a graph) via a direct graph_json.php request with a modified + local_graph_id parameter.

+
+ +
+ + CVE-2019-16723 + https://github.com/Cacti/cacti/releases/tag/release%2F1.2.7 + + + 2019-09-23 + 2019-10-02 + +
+ Exim -- heap-based buffer overflow in string_vformat leading to RCE