Description
Cacti provides an operational monitoring and fault management framework. Version 1.2.25 has a Blind SQL Injection (SQLi) vulnerability within the SNMP Notification Receivers feature in the file `‘managers.php’`. An authenticated attacker with the “Settings/Utilities” permission can send a crafted HTTP GET request to the endpoint `‘/cacti/managers.php’` with an SQLi payload in the `‘selected_graphs_array’` HTTP GET parameter. As of time of publication, no patched versions exist.
Published: 2023-12-22
Score: 8.8 High
EPSS: 32.1% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.28788}

epss

{'score': 0.37545}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-02-13T17:19:45.658Z

Reserved: 2023-12-19T15:19:39.615Z

Link: CVE-2023-51448

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-12-22T17:15:09.960

Modified: 2024-11-21T08:38:08.387

Link: CVE-2023-51448

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses