In Cacti before 1.2.11, auth_profile.php?action=edit allows CSRF for an admin email change.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://github.com/Cacti/cacti/releases/tag/release%2F1.2.11 | release notes |
https://github.com/Cacti/cacti/issues/3342 | issue tracking exploit third party advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q3PCDGNELH7HEBIXRNT5J5EWQEXQAU6B/ | vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ICJMWSY77IIGZYR6FE6NAQZFBO42VECO/ | vendor advisory |