CVE-2023-51448: SQL Injection vulnerability when managing SNMP Notification Receivers
Cacti provides an operational monitoring and fault management framework. Version 1.2.25 has a Blind SQL Injection (SQLi) vulnerability within the SNMP Notification Receivers feature in the file ‘managers.php’. An authenticated attacker with the “Settings/Utilities” permission can send a crafted HTTP GET request to the endpoint ‘/cacti/managers.php’ with an SQLi payload in the ‘selectedgraphsarray’ HTTP GET parameter. As of time of publication, no patched versions exist.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-51448?
CVE-2023-51448 is classified as a High severity vulnerability due to its potential for Blind SQL Injection.
How do I fix CVE-2023-51448?
To fix CVE-2023-51448, update Cacti to version 1.2.26 or later where the vulnerability has been addressed.
What does CVE-2023-51448 affect?
CVE-2023-51448 affects Cacti version 1.2.25 specifically within the SNMP Notification Receivers feature.
Who can exploit CVE-2023-51448?
An authenticated attacker with the 'Settings/Utilities' permission can exploit CVE-2023-51448.
What type of vulnerability is CVE-2023-51448?
CVE-2023-51448 is a Blind SQL Injection (SQLi) vulnerability.