icon

We found results for “

CVE-2023-51448

Date: December 22, 2023

Cacti provides an operational monitoring and fault management framework. Version 1.2.25 has a Blind SQL Injection (SQLi) vulnerability within the SNMP Notification Receivers feature in the file "‘managers.php’". An authenticated attacker with the “Settings/Utilities” permission can send a crafted HTTP GET request to the endpoint "‘/cacti/managers.php’" with an SQLi payload in the "‘selected_graphs_array’" HTTP GET parameter. As of time of publication, no patched versions exist.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CWE-89

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): HIGH

Do you need more information?

Contact Us