CVE-2023-46490: Cacti
Medium severity, CVSS 6.5. EPSS: 1.4% chance of exploitation in the next 30 days.
SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain sensitive information via the form_actions() function in the managers.php function.
Affected products
- Cacti Cacti: version 1.2.25 only
Published 2023-10-27. Last modified 2026-06-17.