SQL Injection Vulnerability in Cacti Performance Management Framework
CVE-2024-54146
8.8HIGH
What is CVE-2024-54146?
The Cacti performance management framework is susceptible to a SQL injection vulnerability found in the template function of the host_templates.php file. This weakness is triggered when the graph_template parameter is manipulated, allowing an attacker to execute arbitrary SQL queries. The issue has been effectively addressed in the latest release, version 1.2.29, ensuring users can securely utilize Cacti without the risk of unauthorized access to their database.
Affected Version(s)
cacti < 1.2.29