CVE-2025-24367

Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*

History

03 Nov 2025, 22:18

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/02/msg00010.html -

Information

Published : 2025-01-27 18:15

Updated : 2025-11-03 22:18


NVD link : CVE-2025-24367

Mitre link : CVE-2025-24367

CVE.ORG link : CVE-2025-24367


JSON object : View

Products Affected

cacti

  • cacti
CWE
CWE-144

Improper Neutralization of Line Delimiters

NVD-CWE-Other