logo

Cacti Monitoring Tool Spiked by Critical SQL Injection Vulnerability

ID: 47b70ab1-8c19-5b7a-9b7d-a046710d97bf

STIX ID: report--47b70ab1-8c19-5b7a-9b7d-a046710d97bf

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-01-08

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

A critical blind SQL injection vulnerability (CVE-2023-51448) in Cacti 1.2.25 allows an authenticated user with Settings/Utilities privileges to exfiltrate the application's entire database and could be chained with CVE-2023-49084 to achieve remote code execution; GitHub assigned CVSS 3.1 a score of 8.8, researchers identified over 4,000 potentially vulnerable hosts via Shodan, and Cacti has released an updated version to address the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.