Summary
As reported by Trend Micro, issues with Cacti Regular Expression validation combined with our external links feature can lead to SQL Injections and subsequent data leakage.
Details
See: ZDI-CAN-20767 and ZDI-CAN-21001
PoC
Is included in the reports.
Impact
Possible unchecked SQL injection and data leakage as reported.
Summary
As reported by Trend Micro, issues with Cacti Regular Expression validation combined with our external links feature can lead to SQL Injections and subsequent data leakage.
Details
See: ZDI-CAN-20767 and ZDI-CAN-21001
PoC
Is included in the reports.
Impact
Possible unchecked SQL injection and data leakage as reported.