Cacti is an open source performance and fault management framework. Prior to 1.2.29, an administrator can change the `Poller Standard Error Log Path` parameter in either Installation Step 5 or in Configuration->Settings->Paths tab to a local file inside the server. Then simply going to Logs tab and selecting the name of the local file will show its content on the web UI. This vulnerability is fixed in 1.2.29.
History

Mon, 27 Jan 2025 16:00:00 +0000

Type Values Removed Values Added
Description Cacti is an open source performance and fault management framework. Prior to 1.2.29, an administrator can change the `Poller Standard Error Log Path` parameter in either Installation Step 5 or in Configuration->Settings->Paths tab to a local file inside the server. Then simply going to Logs tab and selecting the name of the local file will show its content on the web UI. This vulnerability is fixed in 1.2.29.
Title Cacti has a Local File Inclusion (LFI) Vulnerability via Poller Standard Error Log Path
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-01-27T15:46:02.425Z

Updated: 2025-01-27T17:58:19.012Z

Reserved: 2024-09-02T16:00:02.423Z

Link: CVE-2024-45598

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-01-27T16:15:31.267

Modified: 2025-01-27T16:15:31.267

Link: CVE-2024-45598

cve-icon Redhat

No data.