CVE-2014-2327: Cacti
Medium severity, CVSS 6.8. EPSS: 2.3% chance of exploitation in the next 30 days.
Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack the authentication of users for unspecified commands, as demonstrated by requests that (1) modify binary files, (2) modify configurations, or (3) add arbitrary users.
Affected products
- Cacti Cacti: from 0.8.7, up to and including 0.8.7g; from 0.8.8, up to and including 0.8.8b
- Debian Debian Linux: version 7.0 only; version 8.0 only
- Opensuse Opensuse: version 13.1 only; version 13.2 only
Published 2014-04-23. Last modified 2026-06-17.