Cacti Privilege Escalation
CVE-2023-31132
7.8HIGH
What is CVE-2023-31132?
Cacti, an open-source operational monitoring and fault management framework, is affected by a privilege escalation issue. This vulnerability allows an attacker with low-level OS user access on a Windows system hosting Cacti to create arbitrary PHP files in a web document directory. The attacker can execute these files with SYSTEM-level privileges, enabling them to escalate their access beyond a normal user account. Cacti version 1.2.25 addresses this vulnerability, and users are strongly urged to upgrade to protect their systems, as there are no known workarounds.
Affected Version(s)
cacti < 1.2.25