CVE-2024-54146
CVSS 3.1 Score 7.6 of 10 (high)
Details
Published Jan 27, 2025
CWE ID 89
Summary
CVE-2024-54146 is a newly discovered SQL injection vulnerability affecting Cacti, an open-source network monitoring tool. The weakness lies in the template function of the file "host_templates.php" within the application. An attacker can exploit this flaw by manipulating the graph_template parameter to inject malicious SQL statements, potentially leading to unauthorized data access or system compromise. Users are advised to update their Cacti installation to version 1.2.29 to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Cacti
Affected Vendors
- Cacti