← volver
CVE-2023-49085highCWE-89

Cacti SQL Injection vulnerability

58Vexday Risk Score

Corrige pronto. Ella tiene exploit funcional público.

ssvc Attendcvss 8.8epss 85%
de la publicación al arma0 días
Publicada en NVD22 dic
metasploit20 dic
probabilidad de explotación
85%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
Cacti provides an operational monitoring and fault management framework. In versions 1.2.25 and prior, it is possible to execute arbitrary SQL code through the `pollers.php` script. An authorized user may be able to execute arbitrary SQL code. The vulnerable component is the `pollers.php`. Impact of the vulnerability - arbitrary SQL code execution. As of time of publication, a patch does not appear to exist.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Cacti · cacti