PT-2026-52625 · Cacti · Cacti
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Cacti versions prior to 1.2.31
Description
Cacti is an open source performance and fault management framework. The software is subject to Session Fixation because the
session regenerate id() function is not called after a successful login. In the login flow at the 'auth login.php' endpoint, the system directly sets the $ SESSION[SESS USER ID] variable without rotating the session ID. While session cookie configurations include httponly, samesite, and secure flags, these measures do not prevent session fixation via same-site vectors.Recommendations
Update to version 1.2.31.
Exploit
Fix
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cacti