Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29.
History

Fri, 18 Apr 2025 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Cacti
Cacti cacti
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*
Vendors & Products Cacti
Cacti cacti
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Mon, 27 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
Description Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29.
Title Cacti allows Arbitrary File Creation leading to RCE
Weaknesses CWE-144
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-01-27T18:54:38.459Z

Reserved: 2025-01-20T15:18:26.990Z

Link: CVE-2025-24367

cve-icon Vulnrichment

Updated: 2025-01-27T18:54:22.645Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-27T18:15:42.003

Modified: 2025-04-18T02:22:25.780

Link: CVE-2025-24367

cve-icon Redhat

No data.