SQL Injection Vulnerability in Cacti Performance Management Framework
CVE-2024-54146

8.8HIGH

Key Information:

Vendor

Cacti

Status
Vendor
CVE Published:
27 January 2025

What is CVE-2024-54146?

The Cacti performance management framework is susceptible to a SQL injection vulnerability found in the template function of the host_templates.php file. This weakness is triggered when the graph_template parameter is manipulated, allowing an attacker to execute arbitrary SQL queries. The issue has been effectively addressed in the latest release, version 1.2.29, ensuring users can securely utilize Cacti without the risk of unauthorized access to their database.

Affected Version(s)

cacti < 1.2.29

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-54146 : SQL Injection Vulnerability in Cacti Performance Management Framework