CVE-2024-54146

CVSS 3.1 Score 7.6 of 10 (high)

Details

Published Jan 27, 2025
CWE ID 89

Summary

CVE-2024-54146 is a newly discovered SQL injection vulnerability affecting Cacti, an open-source network monitoring tool. The weakness lies in the template function of the file "host_templates.php" within the application. An attacker can exploit this flaw by manipulating the graph_template parameter to inject malicious SQL statements, potentially leading to unauthorized data access or system compromise. Users are advised to update their Cacti installation to version 1.2.29 to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share