PT-2026-52627 · Cacti · Cacti
Publicado
2026-06-25
·
Atualizado
2026-06-25
·
CVE-2026-40084
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal through the Report format file Parameter, causing arbitrary file read. This vulnerability occurs in two stages. In the first stage (stored injection), lib/html reports.php at line 283 stores $save['format file'] = $post['format file'] directly into the database without any validation. In the second stage (file read), lib/reports.php at line 667 concatenates CACTI PATH FORMATS . '/' . $format file, and line 670 then calls file($format file), reading arbitrary files from the filesystem. This issue has been fixed in version 1.2.31.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cacti