ALAS-2024-1915 --- cactiID: oval:org.secpod.oval:def:1601881 | Date: (C)2024-03-05 (M)2024-06-17 |
Class: PATCH | Family: unix |
Cacti provides an operational monitoring and fault management framework. Version 1.2.25 has a Blind SQL Injection vulnerability within the SNMP Notification Receivers feature in the file 'managers.php'. An authenticated attacker with the "Settings/Utilities" permission can send a crafted HTTP GET request to the endpoint '/cacti/managers.php' with an SQLi payload in the 'selected_graphs_array' HTTP GET parameter. As of time of publication, no patched versions exist
Platform: |
Amazon Linux AMI |