← back
CVE-2023-49085highCWE-89

Cacti SQL Injection vulnerability

58Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 8.8epss 85%
from disclosure to weapon0 days
Published on NVDDec 22
metasploitDec 20
exploitation probability
85%top 1% of all CVEs
observed exploitation
nono source reports it
Cacti provides an operational monitoring and fault management framework. In versions 1.2.25 and prior, it is possible to execute arbitrary SQL code through the `pollers.php` script. An authorized user may be able to execute arbitrary SQL code. The vulnerable component is the `pollers.php`. Impact of the vulnerability - arbitrary SQL code execution. As of time of publication, a patch does not appear to exist.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Cacti · cacti