CVE-2023-49085: Cacti SQL Injection vulnerability
Cacti provides an operational monitoring and fault management framework. In versions 1.2.25 and prior, it is possible to execute arbitrary SQL code through the pollers.php script. An authorized user may be able to execute arbitrary SQL code. The vulnerable component is the pollers.php. Impact of the vulnerability - arbitrary SQL code execution. As of time of publication, a patch does not appear to exist.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49085?
CVE-2023-49085 has a high severity rating due to its potential for arbitrary SQL code execution.
How do I fix CVE-2023-49085?
To fix CVE-2023-49085, upgrade Cacti to version 1.2.26 or later.
What versions are affected by CVE-2023-49085?
CVE-2023-49085 affects Cacti versions 1.2.25 and prior.
Can an unauthorized user exploit CVE-2023-49085?
No, only authorized users can exploit CVE-2023-49085 to execute arbitrary SQL code.
What component of Cacti is vulnerable in CVE-2023-49085?
The vulnerable component in CVE-2023-49085 is the pollers.php script.