SQL Injection Vulnerability in Cacti Performance Management Framework
CVE-2024-54145
8.8HIGH
What is CVE-2024-54145?
Cacti, an open-source performance and fault management framework, has been found to have a significant SQL injection vulnerability within its get_discovery_results function located in automation_devices.php. This vulnerability exploits the network parameter, potentially allowing unauthorized users to execute malicious SQL queries. Users are strongly encouraged to upgrade to Cacti version 1.2.29 or later to mitigate this security risk. For further details and updates, please refer to the provided advisory links.
Affected Version(s)
cacti < 1.2.29