PT-2026-52627 · Cacti · Cacti
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cacti versions prior to 1.2.31
Description
Cacti is an open source performance and fault management framework. A path traversal issue allows for arbitrary file read through the Report
format file parameter. The process occurs in two stages: first, a stored injection where lib/html reports.php stores the format file value into the database without validation; second, lib/reports.php concatenates the value with a path and uses the file() function to read arbitrary files from the filesystem.Recommendations
Update to version 1.2.31.
Exploit
Fix
DoS
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cacti