Back to search
CVE-2025-24368
Published: Jan 27, 2025
Modified: Nov 3, 2025
PUBLISHED
Description
Cacti is an open source performance and fault management framework. Some of the data stored in automation_tree_rules.php is not thoroughly checked and is used to concatenate the SQL statement in build_rule_item_filter() function from lib/api_automation.php, resulting in SQL injection. This vulnerability is fixed in 1.2.29.
| Vendor | Product | Versions |
|---|---|---|
Cacti | cacti | affected < 1.2.29 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now