Bug#1059286: cacti: CVE-2023-46490

2023-12-22 Thread Paul Gevers
Hi, On 22-12-2023 13:17, Moritz Mühlenhoff wrote: There's also a reference for https://github.com/Cacti/cacti/security/advisories/GHSA-f4r3-53jr-654c but it's noin-public for two months now, might be worth checking with upstream for the status. Upstream confirmed they are working on an

Bug#1059286: cacti: CVE-2023-46490

2023-12-22 Thread Moritz Mühlenhoff
Source: cacti X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for cacti. CVE-2023-46490[0]: | SQL Injection vulnerability in Cacti v1.2.25 allows a remote | attacker to obtain sensitive information via the form_actions() |