CVE-2023-46490: SQL Injection
Published Oct 27, 2023
·Updated
SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain sensitive information via the formactions() function in the managers.php function.
Affected Software
1 affected component
Cacti Cacti=1.2.25
Event History
Oct 27, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for the SQL Injection vulnerability in Cacti v1.2.25?
The vulnerability ID for the SQL Injection vulnerability in Cacti v1.2.25 is CVE-2023-46490.
2
What is the severity of CVE-2023-46490?
The severity of CVE-2023-46490 is medium, with a CVSS score of 6.5.
3
How does the SQL Injection vulnerability in Cacti v1.2.25 occur?
The SQL Injection vulnerability in Cacti v1.2.25 occurs due to improper input validation in the form_actions() function in the managers.php file.
4
What can a remote attacker achieve through the SQL Injection vulnerability in Cacti v1.2.25?
A remote attacker can obtain sensitive information through the SQL Injection vulnerability in Cacti v1.2.25.
5
How can I fix the SQL Injection vulnerability in Cacti v1.2.25?
To fix the SQL Injection vulnerability in Cacti v1.2.25, update to a version that is not affected by this vulnerability.