CVE-2024-31458 Information
May 15, 2024
cve
Description
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27 some of the data stored in form_save() function in graph_template_inputs.php is not thoroughly checked and is used to concatenate the SQL statement in draw_nontemplated_fields_graph_item() function from lib/html_form_templates.php finally resulting in SQL injection. Version 1.2.27 contains a patch for the issue.
Reference
https://github.com/Cacti/cacti/security/advisories/GHSA-jrxg-8wh8-943x
Share on: