CVE-2023-51448
22.12.2023, 17:15
Cacti provides an operational monitoring and fault management framework. Version 1.2.25 has a Blind SQL Injection (SQLi) vulnerability within the SNMP Notification Receivers feature in the file `managers.php`. An authenticated attacker with the Settings/Utilities permission can send a crafted HTTP GET request to the endpoint `/cacti/managers.php` with an SQLi payload in the `selected_graphs_array` HTTP GET parameter. As of time of publication, no patched versions exist.
Vendor | Product | Version |
---|---|---|
cacti | cacti | 1.2.25 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References