SQL Injection Vulnerability in Cacti Performance Management Framework
CVE-2025-24368
6.9MEDIUM
What is CVE-2025-24368?
Cacti, an open-source performance and fault management framework, is vulnerable to SQL injection due to insufficient validation of input data in the automation_tree_rules.php file. This flaw allows unauthenticated users to manipulate SQL queries through the build_rule_item_filter() function in lib/api_automation.php, potentially leading to unauthorized access and data exposure. The issue has been addressed in version 1.2.29 with crucial security updates.
Affected Version(s)
cacti < 1.2.29