HTTP: Cacti Group Cacti managers.php SQL Injection
This signature detects attempts to exploit a known vulnerability against Cacti Group. A successful attack can lead to command injection and arbitrary code execution.
Extended Description
Cacti provides an operational monitoring and fault management framework. Version 1.2.25 has a Blind SQL Injection (SQLi) vulnerability within the SNMP Notification Receivers feature in the file `managers.php`. An authenticated attacker with the Settings/Utilities permission can send a crafted HTTP GET request to the endpoint `/cacti/managers.php` with an SQLi payload in the `selected_graphs_array` HTTP GET parameter. As of time of publication, no patched versions exist.
Affected Products
Cacti cacti
References
CVE: CVE-2023-51448
URL: https://github.com/Cacti/cacti/security/advisories/GHSA-w85f-7c4w-7594
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Cacti