CVE-2024-43362
- EPSS 3.46%
- Veröffentlicht 07.10.2024 21:15:15
- Zuletzt bearbeitet 03.11.2025 21:16:18
Cacti is an open source performance and fault management framework. The `fileurl` parameter is not properly sanitized when saving external links in `links.php` . Morever, the said fileurl is placed in some html code which is passed to the `print` fun...
CVE-2024-43363
- EPSS 73.1%
- Veröffentlicht 07.10.2024 21:15:15
- Zuletzt bearbeitet 03.11.2025 21:16:18
Cacti is an open source performance and fault management framework. An admin user can create a device with a malicious hostname containing php code and repeat the installation process (completing only step 5 of the installation process is enough, no ...
CVE-2024-34340
- EPSS 0.88%
- Veröffentlicht 14.05.2024 15:38:39
- Zuletzt bearbeitet 04.11.2025 17:15:53
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set their password. `compat_password_hash` use `password_hash` if there is it, else use `md5`. When verify...
CVE-2024-31459
- EPSS 3.1%
- Veröffentlicht 14.05.2024 15:25:26
- Zuletzt bearbeitet 04.11.2025 17:15:50
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, there is a file inclusion issue in the `lib/plugin.php` file. Combined with SQL injection vulnerabilities, remote code execution can be implemented. The...
CVE-2024-31460
- EPSS 1.84%
- Veröffentlicht 14.05.2024 15:25:26
- Zuletzt bearbeitet 04.11.2025 17:15:51
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the SQL statement in `create_all_header_node...
- EPSS 6.02%
- Veröffentlicht 14.05.2024 15:25:25
- Zuletzt bearbeitet 04.11.2025 17:15:50
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `form_save()` function in `graph_template_inputs.php` is not thoroughly checked and is used to concatenate the SQL statement ...
CVE-2024-31445
- EPSS 52.19%
- Veröffentlicht 14.05.2024 15:25:21
- Zuletzt bearbeitet 04.11.2025 17:15:50
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, a SQL injection vulnerability in `automation_get_new_graphs_sql` function of `api_automation.php` allows authenticated users to exploit these SQL inject...
CVE-2024-31443
- EPSS 0.64%
- Veröffentlicht 14.05.2024 15:25:20
- Zuletzt bearbeitet 04.11.2025 17:15:50
Cacti provides an operational monitoring and fault management framework. Prior to 1.2.27, some of the data stored in `form_save()` function in `data_queries.php` is not thoroughly checked and is used to concatenate the HTML statement in `grow_right_p...
CVE-2024-31444
- EPSS 9.4%
- Veröffentlicht 14.05.2024 15:25:20
- Zuletzt bearbeitet 04.11.2025 17:15:50
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules_form_save()` function in `automation_tree_rules.php` is not thoroughly checked and is used to concaten...
CVE-2024-30268
- EPSS 0.2%
- Veröffentlicht 14.05.2024 15:22:18
- Zuletzt bearbeitet 21.11.2024 09:11:35
Cacti provides an operational monitoring and fault management framework. A reflected cross-site scripting vulnerability on the 1.3.x DEV branch allows attackers to obtain cookies of administrator and other users and fake their login using obtained co...