CVE-2024-31444
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data store
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in automation_tree_rules_form_save() function in automation_tree_rules.php is not thoroughly checked and is used to concatenate the HTML statement in form_confirm() function from lib/html.php , finally resulting in cross-site scripting. Version 1.2.27 contains a patch for the issue.
MEDIUM · CVSS 4.6
EPSS 0.09401
Schedule remediation
- EPSS percentile: top 7% of all CVEs by exploitation likelihood
- Public exploit or PoC is available
Sigma rules0
YARA rules0