CVE-2025-24368
Severity CVSS v4.0:
MEDIUM
Type:
CWE-89
SQL Injection
Publication date:
27/01/2025
Last modified:
03/11/2025
Description
Cacti is an open source performance and fault management framework. Some of the data stored in automation_tree_rules.php is not thoroughly checked and is used to concatenate the SQL statement in build_rule_item_filter() function from lib/api_automation.php, resulting in SQL injection. This vulnerability is fixed in 1.2.29.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:* | 1.2.29 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



