Vulnerability record · CVE-2023-49084 · published 21 December 2023
CVE-2023-49084: Cacti link.php SQL injection and file path flaw enables remote code execution
Cacti · Cacti
Cacti's link.php combines a detected SQL injection with insufficient processing of an include file path, allowing arbitrary code execution on the server. The flaw requires an authorized user, so it is a post-authentication issue that still yields full server compromise.
Description
Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL Injection and insufficient processing of the include file path, it is possible to execute arbitrary code on the server. Exploitation of the vulnerability is possible for an authorized user. The vulnerable component is the `link.php`. Impact of the vulnerability execution of arbitrary code on the server.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with high EPSS and a vendor advisory tagged Exploit, though exploitation requires an authenticated account.
What it is
Cacti's link.php combines a detected SQL injection with insufficient processing of an include file path, allowing arbitrary code execution on the server. The flaw requires an authorized user, so it is a post-authentication issue that still yields full server compromise.
Impact
An authenticated attacker can execute arbitrary code on the Cacti server, leading to full compromise of confidentiality, integrity and availability.
Attack surface
Reached over the network via the link.php component with low attack complexity and no user interaction, but it requires a valid authenticated session (PR:L).
Exploitation
Not listed in CISA KEV, but EPSS is 0.64202 (99.192 percentile) and the vendor advisory is tagged Exploit, indicating public exploit material exists.
What to do
- Apply the Cacti security fix referenced in vendor advisory GHSA-pfh9-gwm6-86vp and upgrade to a patched release.
- Apply the Debian LTS and Fedora package updates for Cacti.
- Restrict Cacti access to trusted networks and enforce least privilege on Cacti accounts.
- Review and harden PHP include path handling and input validation around link.php.
- Monitor Cacti accounts for unexpected privilege use or anomalous requests.
Detection
- Inspect web logs for suspicious requests to link.php containing SQL or path traversal patterns.
- Monitor for unexpected PHP file creation or modification in Cacti web directories.
- Alert on outbound connections or process execution spawned by the web server user.
- Audit Cacti user accounts for unusual login or activity patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-49084 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-49084), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.