Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29.
History

Mon, 27 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
Description Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29.
Title Cacti allows Arbitrary File Creation leading to RCE
Weaknesses CWE-144
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-01-27T17:12:40.174Z

Updated: 2025-01-27T18:54:38.459Z

Reserved: 2025-01-20T15:18:26.990Z

Link: CVE-2025-24367

cve-icon Vulnrichment

Updated: 2025-01-27T18:54:22.645Z

cve-icon NVD

Status : Received

Published: 2025-01-27T18:15:42.003

Modified: 2025-01-27T19:15:29.440

Link: CVE-2025-24367

cve-icon Redhat

No data.