CVE-2024-31458
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data store
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in form_save() function in graph_template_inputs.php is not thoroughly checked and is used to concatenate the SQL statement in draw_nontemplated_fields_graph_item() function from lib/html_form_templates.php , finally resulting in SQL injection. Version 1.2.27 contains a patch for the issue.
MEDIUM · CVSS 4.6
EPSS 0.06015
Schedule remediation
- EPSS percentile: top 9% of all CVEs by exploitation likelihood
- Public exploit or PoC is available
Sigma rules0
YARA rules0