CVE-2023-51448
EUVD-2023-5616322.12.2023, 17:15
Cacti provides an operational monitoring and fault management framework. Version 1.2.25 has a Blind SQL Injection (SQLi) vulnerability within the SNMP Notification Receivers feature in the file `‘managers.php’`. An authenticated attacker with the “Settings/Utilities” permission can send a crafted HTTP GET request to the endpoint `‘/cacti/managers.php’` with an SQLi payload in the `‘selected_graphs_array’` HTTP GET parameter. As of time of publication, no patched versions exist.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cacti | cacti | 1.2.25 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References