Hello to everyone,
I detected a breach in my cacti 0.8.6i. Once I logout with a regular user from cacti I push back button on my browser and a list of all the clients are fully shown. So every customer is able to view the rest of clients graphs.
Putting directly http://serverdomain/graph_view.php on my browser I'm also able to list all users without any other action (as trying to log in first) and enter each one.
Is there anything to do with my version of cacti? I was wondering if there is a way around to get rid of this.
Thanks for your help.
Dmo
All the user graphs are listed to everyone
Moderators: Developers, Moderators
Who is online
Users browsing this forum: No registered users and 2 guests