PT-2026-52134 · Cacti · Cacti
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Cacti versions prior to 1.2.31
Description
Cacti is an open source performance and fault management framework. The software contains a path traversal flaw in the 'package import.php' endpoint, where the
filename parameter is not properly validated. Path traversal is a vulnerability that allows an attacker to access files and directories that are stored outside the web root folder.Recommendations
Update to version 1.2.31.
Avoid using the
filename parameter in the 'package import.php' endpoint until the update is applied.Exploit
Fix
DoS
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cacti