CVE-2023-49085

HIGH

Cacti <1.2.25 - SQL Injection

Title source: llm

Description

Cacti provides an operational monitoring and fault management framework. In versions 1.2.25 and prior, it is possible to execute arbitrary SQL code through the `pollers.php` script. An authorized user may be able to execute arbitrary SQL code. The vulnerable component is the `pollers.php`. Impact of the vulnerability - arbitrary SQL code execution. As of time of publication, a patch does not appear to exist.

Exploits (1)

metasploit WORKING POC EXCELLENT
by Aleksey Solovev, Christophe De La Fuente · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/cacti_pollers_sqli_rce.rb

Scores

CVSS v3 8.8
EPSS 0.9140
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
cacti/cacti < 1.2.25
Published Dec 22, 2023
Tracked Since Feb 18, 2026