Cacti 1.2.28

CPE Details

Cacti 1.2.28
1.2.28
2025-03-04
12h28 +00:00
2025-03-04
12h28 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:cacti:cacti:1.2.28:*:*:*:*:*:*:*

Informations

Vendor

cacti

Product

cacti

Version

1.2.28

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-24368 2025-01-27 17h16 +00:00 Cacti is an open source performance and fault management framework. Some of the data stored in automation_tree_rules.php is not thoroughly checked and is used to concatenate the SQL statement in build_rule_item_filter() function from lib/api_automation.php, resulting in SQL injection. This vulnerability is fixed in 1.2.29.
6.9
Medium
CVE-2025-24367 2025-01-27 17h12 +00:00 Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29.
8.7
High