← Back to browse · API

CVE-2023-49085

Severity
HIGH
CVSS
8.8
EPSS
0.84628
Risk score
64.82
CISA KEV
No
PoC
No
Published
2023-12-22
Modified
2026-02-25
First seen
2026-08-07
Aliases
EUVD-2023-53100
Products
Cacti:cacti ≤ 1.2.25
Sources
euvd EUVD-2023-53100

Description

Cacti provides an operational monitoring and fault management framework. In versions 1.2.25 and prior, it is possible to execute arbitrary SQL code through the `pollers.php` script. An authorized user may be able to execute arbitrary SQL code. The vulnerable component is the `pollers.php`. Impact of the vulnerability - arbitrary SQL code execution. As of time of publication, a patch does not appear to exist.

References