VYPR
High severity8.8NVD Advisory· Published Jan 27, 2025· Updated Jun 17, 2026

CVE-2025-24367

CVE-2025-24367

Description

Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*range: <1.2.29
    • (no CPE)range: >=1.2.29
    • (no CPE)range: <= 1.2.28

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.