CVE-2025-24367CWE-144

Cacti allows Arbitrary File Creation leading to RCE

High · published January 27, 2025

Patch now

High probability of exploitation

CVSS calls it high at 8.7. It sits in the 98.9th percentile for exploit probability.

CVSS v4.0
8.7
EPSS
54%
Percentile
98.9
In the wild
Unconfirmed
What it is

Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29.

The record
Technical detail
CVSS v4.0
8.7 · HIGH
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.54024 · 98.9th percentile
Weakness
CWE-144 · Improper Neutralization of Line Delimiters
Published
2025-01-27T17:12Z
EPSS history
Timeline
  • 27 JAN 17:12Z
    Cacti allows Arbitrary File Creation leading to RCE
    cvelistv5