Cacti Monitoring Tool Spiked by Critical SQL Injection Vulnerability
ID: 47b70ab1-8c19-5b7a-9b7d-a046710d97bf
STIX ID: report--47b70ab1-8c19-5b7a-9b7d-a046710d97bf
Feed Name: Dark Reading
Threat Score
A critical blind SQL injection vulnerability (CVE-2023-51448) in Cacti 1.2.25 allows an authenticated user with Settings/Utilities privileges to exfiltrate the application's entire database and could be chained with CVE-2023-49084 to achieve remote code execution; GitHub assigned CVSS 3.1 a score of 8.8, researchers identified over 4,000 potentially vulnerable hosts via Shodan, and Cacti has released an updated version to address the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
