cve/2023/CVE-2023-51448.md
2024-06-07 17:53:02 +00:00

1.2 KiB
Raw Blame History

CVE-2023-51448

Description

Cacti provides an operational monitoring and fault management framework. Version 1.2.25 has a Blind SQL Injection (SQLi) vulnerability within the SNMP Notification Receivers feature in the file managers.php. An authenticated attacker with the “Settings/Utilities” permission can send a crafted HTTP GET request to the endpoint /cacti/managers.php with an SQLi payload in the selected_graphs_array HTTP GET parameter. As of time of publication, no patched versions exist.

POC

Reference

Github