Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29.
References
Link | Resource |
---|---|
https://github.com/Cacti/cacti/commit/c7e4ee798d263a3209ae6e7ba182c7b65284d8f0 | Patch |
https://github.com/Cacti/cacti/security/advisories/GHSA-fxrq-fr7h-9rqq | Exploit Vendor Advisory |
https://github.com/Cacti/cacti/security/advisories/GHSA-fxrq-fr7h-9rqq | Exploit Vendor Advisory |
Configurations
History
18 Apr 2025, 02:22
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
First Time |
Cacti cacti
Cacti |
|
CPE | cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
CWE | NVD-CWE-Other | |
References | () https://github.com/Cacti/cacti/commit/c7e4ee798d263a3209ae6e7ba182c7b65284d8f0 - Patch | |
References | () https://github.com/Cacti/cacti/security/advisories/GHSA-fxrq-fr7h-9rqq - Exploit, Vendor Advisory |
27 Jan 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/Cacti/cacti/security/advisories/GHSA-fxrq-fr7h-9rqq - |
27 Jan 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-27 18:15
Updated : 2025-04-18 02:22
NVD link : CVE-2025-24367
Mitre link : CVE-2025-24367
CVE.ORG link : CVE-2025-24367
JSON object : View
Products Affected
cacti
- cacti
CWE