Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29.
References
Link | Resource |
---|---|
https://github.com/Cacti/cacti/commit/c7e4ee798d263a3209ae6e7ba182c7b65284d8f0 | Patch |
https://github.com/Cacti/cacti/security/advisories/GHSA-fxrq-fr7h-9rqq | Exploit Vendor Advisory |
https://github.com/Cacti/cacti/security/advisories/GHSA-fxrq-fr7h-9rqq | Exploit Vendor Advisory |
Configurations
History
18 Apr 2025, 02:22
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CPE | cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:* | |
References | () https://github.com/Cacti/cacti/commit/c7e4ee798d263a3209ae6e7ba182c7b65284d8f0 - Patch | |
References | () https://github.com/Cacti/cacti/security/advisories/GHSA-fxrq-fr7h-9rqq - Exploit, Vendor Advisory | |
CWE | NVD-CWE-Other | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
First Time |
Cacti
Cacti cacti |
27 Jan 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/Cacti/cacti/security/advisories/GHSA-fxrq-fr7h-9rqq - |
27 Jan 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-27 18:15
Updated : 2025-04-18 02:22
NVD link : CVE-2025-24367
Mitre link : CVE-2025-24367
CVE.ORG link : CVE-2025-24367
JSON object : View
Products Affected
cacti
- cacti
CWE