SQL Injection Vulnerability in Cacti Performance Management Framework
CVE-2025-24368
6.9MEDIUM
What is CVE-2025-24368?
Cacti, an open-source performance and fault management framework, is vulnerable to SQL injection due to insufficient validation of input data in the automation_tree_rules.php file. This flaw allows unauthenticated users to manipulate SQL queries through the build_rule_item_filter() function in lib/api_automation.php, potentially leading to unauthorized access and data exposure. The issue has been addressed in version 1.2.29 with crucial security updates.
Affected Version(s)
cacti < 1.2.29
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
