SQL Injection Vulnerability in Cacti Performance Management Framework
CVE-2025-24368

6.9MEDIUM

Key Information:

Vendor

Cacti

Status
Vendor
CVE Published:
27 January 2025

What is CVE-2025-24368?

Cacti, an open-source performance and fault management framework, is vulnerable to SQL injection due to insufficient validation of input data in the automation_tree_rules.php file. This flaw allows unauthenticated users to manipulate SQL queries through the build_rule_item_filter() function in lib/api_automation.php, potentially leading to unauthorized access and data exposure. The issue has been addressed in version 1.2.29 with crucial security updates.

Affected Version(s)

cacti < 1.2.29

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.