{"id":"CVE-2023-46490","details":"SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain sensitive information via the form_actions() function in the managers.php function.","aliases":["GHSA-f4r3-53jr-654c"],"modified":"2026-08-12T03:51:11.788548970Z","published":"2023-10-27T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/46xxx/CVE-2023-46490.json"},"references":[{"type":"WEB","url":"https://gist.github.com/ISHGARD-2/a95632111138fcd7ccf7432ccb145b53"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/46xxx/CVE-2023-46490.json"},{"type":"ADVISORY","url":"https://github.com/Cacti/cacti/security/advisories/GHSA-f4r3-53jr-654c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-46490"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cacti/cacti","events":[{"introduced":"18500fa313a9f1ee1be48aa111c0eeea001010fa"},{"last_affected":"18500fa313a9f1ee1be48aa111c0eeea001010fa"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:cacti:cacti:1.2.25:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.2.25"},{"last_affected":"1.2.25"}]}}],"versions":["1.2.25","release/1.2.25"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-46490.json"}}],"schema_version":"1.9.0"}