← voltar
CVE-2023-49085highCWE-89

Cacti SQL Injection vulnerability

58Vexday Risk Score

Corrija em breve. Ela tem exploit funcional público.

ssvc Attendcvss 8.8epss 85%
da publicação à arma0 dias
Publicada no NVD22 de dez.
metasploit20 de dez.
probabilidade de exploração
85%top 1% das CVEs
exploração observada
nãonenhuma fonte reporta
Cacti provides an operational monitoring and fault management framework. In versions 1.2.25 and prior, it is possible to execute arbitrary SQL code through the `pollers.php` script. An authorized user may be able to execute arbitrary SQL code. The vulnerable component is the `pollers.php`. Impact of the vulnerability - arbitrary SQL code execution. As of time of publication, a patch does not appear to exist.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
Cacti · cacti