by @jakaba
12 Mar 2024

Blind SQL injection in Cacti (CVE-2023-51448)

by @jakaba
12 Mar 2024

Blind SQL injection in Cacti (CVE-2023-51448)

CVEs

8.8 High Severity

Apps

Cacti
CactiCacti
0.8.8C.*
0.6.8A.*
0.8.6G.*
0.8.5A.*
0.8.7I.*
0.8.7G.*
0.8.6D.*
0.8.7C.*
0.8.6K.*
0.8.8F.*

Screenshots from the blog posts

images/cltfz03umfg7m1ioddfbicdl4.jpgimages/cltfz03umfg7m1ioddfbicdl4.jpg

Summary

CVE-2023-51448, a blind SQL injection vulnerability within Cacti's SNMP Notification Receivers, presents a critical threat, allowing authenticated attackers to potentially execute remote code.

Description

users/photos/clj8b3h1k16g10uoihwvzgsxi.png

@jakaba

74 posts

Total vcoins

0

Social media links

Comments (0)