Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4048-1 | cacti security update |
Debian DSA |
DSA-5862-1 | cacti security update |
EUVD |
EUVD-2025-3681 | Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 03 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 18 Apr 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cacti
Cacti cacti |
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cacti
Cacti cacti |
|
| Metrics |
cvssV3_1
|
Mon, 27 Jan 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Jan 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29. | |
| Title | Cacti allows Arbitrary File Creation leading to RCE | |
| Weaknesses | CWE-144 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-03T21:12:40.550Z
Reserved: 2025-01-20T15:18:26.990Z
Link: CVE-2025-24367
Updated: 2025-11-03T21:12:40.550Z
Status : Modified
Published: 2025-01-27T18:15:42.003
Modified: 2025-11-03T22:18:40.307
Link: CVE-2025-24367
No data.
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD