NA

CVE-2023-46490

Published: 27/10/2023 Updated: 13/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

SQL Injection vulnerability in Cacti v1.2.25 allows a remote malicious user to obtain sensitive information via the form_actions() function in the managers.php function.

Vulnerable Product Search on Vulmon Subscribe to Product

cacti cacti 1.2.25

Vendor Advisories

Debian Bug report logs - #1059286 cacti: CVE-2023-46490 Package: src:cacti; Maintainer for src:cacti is Cacti Maintainer <pkg-cacti-maint@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 22 Dec 2023 12:18:13 UTC Severity: important Tags: security, upstream Reply or subscribe ...