CVE-2023-49085
HIGHCacti <1.2.25 - SQL Injection
Title source: llmDescription
Cacti provides an operational monitoring and fault management framework. In versions 1.2.25 and prior, it is possible to execute arbitrary SQL code through the `pollers.php` script. An authorized user may be able to execute arbitrary SQL code. The vulnerable component is the `pollers.php`. Impact of the vulnerability - arbitrary SQL code execution. As of time of publication, a patch does not appear to exist.
Exploits (1)
metasploit
WORKING POC
EXCELLENT
by Aleksey Solovev, Christophe De La Fuente · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/cacti_pollers_sqli_rce.rb
References (5)
Scores
CVSS v3
8.8
EPSS
0.9140
EPSS Percentile
99.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
cacti/cacti
< 1.2.25
Published
Dec 22, 2023
Tracked Since
Feb 18, 2026