CVE-2017-1000031: Cacti

High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.

SQL injection vulnerability in graph_templates_inputs.php in Cacti 0.8.8b allows remote attackers to execute arbitrary SQL commands via the graph_template_input_id and graph_template_id parameters.

Affected products

  • Cacti Cacti: version 0.8.8b only

Published 2017-07-17. Last modified 2026-06-17.