First published: Fri Oct 27 2023(Updated: )
SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain sensitive information via the form_actions() function in the managers.php function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
=1.2.25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the SQL Injection vulnerability in Cacti v1.2.25 is CVE-2023-46490.
The severity of CVE-2023-46490 is medium, with a CVSS score of 6.5.
The SQL Injection vulnerability in Cacti v1.2.25 occurs due to improper input validation in the form_actions() function in the managers.php file.
A remote attacker can obtain sensitive information through the SQL Injection vulnerability in Cacti v1.2.25.
To fix the SQL Injection vulnerability in Cacti v1.2.25, update to a version that is not affected by this vulnerability.