PT-2025-1311 · Cacti · Cacti

Ishgard-2

·

Published

2025-01-26

·

Updated

2025-02-25

·

CVE-2025-24368

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cacti versions prior to 1.2.29
Description The issue is related to the build rule item filter() function in the api automation.php script of the Cacti network monitoring tool, which fails to properly protect the SQL query structure. This can allow a remote attacker to execute arbitrary code. The vulnerability is caused by the concatenation of SQL statements using unchecked data from automation tree rules.php.
Recommendations For versions prior to 1.2.29, update to version 1.2.29 to resolve the issue. As a temporary workaround, consider restricting access to the build rule item filter() function in lib/api automation.php until the update is applied.

Exploit

Fix

RCE

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-00969
CVE-2025-24368
DLA-4048-1
DSA-5862-1
GHSA-F9C7-7RC3-574C

Affected Products

Cacti