Cacti Log Poisoning Vulnerability Affects All Users, Upgrade to 1.2.28 Immediately
CVE-2024-43363
7.2HIGH
What is CVE-2024-43363?
A vulnerability exists in Cacti, an open source performance and fault management framework, where an admin user can create a device with a malicious hostname that contains PHP code. By manipulating the installation process, specifically completing only a particular step, an attacker can achieve log poisoning. This allows the PHP code to be logged and subsequently accessed via the log file URL, leading to potential remote code execution (RCE). This critical issue has been resolved in version 1.2.28, and it is strongly recommended that users update their installations immediately, as there are no known workarounds to mitigate the risk.
Affected Version(s)
cacti < 1.2.28