Cacti

Cacti

137 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.1%
  • Published 14.05.2024 15:17:14
  • Last modified 18.12.2024 21:10:38

Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a residual cross-site scripting vulnerability caused by an incomplete fix for CVE-2023-50250. `raise_message_javascript` from `lib/func...

Exploit
  • EPSS 0.3%
  • Published 14.05.2024 15:11:27
  • Last modified 18.12.2024 21:01:17

Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 are vulnerable to stored cross-site scripting, a type of cross-site scripting where malicious scripts are permanently stored on a target server...

Exploit
  • EPSS 89.04%
  • Published 14.05.2024 15:05:50
  • Last modified 18.12.2024 20:54:30

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable through the "Package Import" feature, allows authenticated users having the "Import Templates" permis...

Exploit
  • EPSS 2%
  • Published 22.12.2023 17:15:09
  • Last modified 10.04.2025 20:31:34

Cacti is an open source operational monitoring and fault management framework. A reflection cross-site scripting vulnerability was discovered in version 1.2.25. Attackers can exploit this vulnerability to perform actions on behalf of other users. The...

Exploit
  • EPSS 37.55%
  • Published 22.12.2023 17:15:09
  • Last modified 21.11.2024 08:38:08

Cacti provides an operational monitoring and fault management framework. Version 1.2.25 has a Blind SQL Injection (SQLi) vulnerability within the SNMP Notification Receivers feature in the file `‘managers.php’`. An authenticated attacker with the “Se...

Exploit
  • EPSS 0.98%
  • Published 22.12.2023 17:15:08
  • Last modified 21.11.2024 08:32:47

Cacti is an open source operational monitoring and fault management framework. The fix applied for CVE-2023-39515 in version 1.2.25 is incomplete as it enables an adversary to have a victim browser execute malicious code when a victim user hovers the...

Exploit
  • EPSS 91.4%
  • Published 22.12.2023 17:15:07
  • Last modified 21.11.2024 08:32:47

Cacti provides an operational monitoring and fault management framework. In versions 1.2.25 and prior, it is possible to execute arbitrary SQL code through the `pollers.php` script. An authorized user may be able to execute arbitrary SQL code. The vu...

Exploit
  • EPSS 0.95%
  • Published 22.12.2023 00:15:34
  • Last modified 11.04.2025 14:50:15

Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). A vulnerability in versions prior to 1.2.27 bypasses an earlier fix for CVE-2023-39360, therefore leading to a DOM XSS attack. Exp...

Exploit
  • EPSS 88.34%
  • Published 21.12.2023 23:15:09
  • Last modified 21.11.2024 08:32:47

Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL Injection and insufficient processing of the include file path, it is possible to execute arbitrary c...

Exploit
  • EPSS 0.21%
  • Published 27.10.2023 22:15:09
  • Last modified 21.11.2024 08:28:35

SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain sensitive information via the form_actions() function in the managers.php function.