Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-31460

Опубликовано: 14 мая 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.5

Описание

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in automation_tree_rules.php is not thoroughly checked and is used to concatenate the SQL statement in create_all_header_nodes() function from lib/api_automation.php , finally resulting in SQL injection. Using SQL based secondary injection technology, attackers can modify the contents of the Cacti database, and based on the modified content, it may be possible to achieve further impact, such as arbitrary file reading, and even remote code execution through arbitrary file writing. Version 1.2.27 contains a patch for the issue.

РелизСтатусПримечание
devel

not-affected

1.2.27+ds1-2
esm-apps/bionic

released

1.1.38+ds1-1ubuntu0.1~esm3
esm-apps/focal

released

1.2.10+ds1-1ubuntu1.1
esm-apps/jammy

released

1.2.19+ds1-2ubuntu1.1
esm-apps/noble

released

1.2.26+ds1-1ubuntu0.1
esm-apps/xenial

not-affected

code not exist
esm-infra-legacy/trusty

not-affected

code not exist
focal

released

1.2.10+ds1-1ubuntu1.1
jammy

released

1.2.19+ds1-2ubuntu1.1
mantic

ignored

end of life, was needs-triage

Показывать по

EPSS

Процентиль: 82%
0.01692
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
больше 1 года назад

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the SQL statement in `create_all_header_nodes()` function from `lib/api_automation.php` , finally resulting in SQL injection. Using SQL based secondary injection technology, attackers can modify the contents of the Cacti database, and based on the modified content, it may be possible to achieve further impact, such as arbitrary file reading, and even remote code execution through arbitrary file writing. Version 1.2.27 contains a patch for the issue.

CVSS3: 6.5
debian
больше 1 года назад

Cacti provides an operational monitoring and fault management framewor ...

CVSS3: 6.5
fstec
больше 1 года назад

Уязвимость функции create_all_header_nodes() программного средства мониторинга сети Cacti, позволяющая нарушителю выполнять произвольные SQL-запросы

suse-cvrf
больше 1 года назад

Security update for cacti, cacti-spine

suse-cvrf
больше 1 года назад

Security update for cacti, cacti-spine

EPSS

Процентиль: 82%
0.01692
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2024-31460