Add CVE-2024-25641 to the inventory.
Authenticated users with "Import Templates" permission can craft a malicious package that abuses the template import feature to perform arbitrary file writes. This allows execution of PHP code on the server by placing files under the web root.
Section: ctf/monitoring/cacti/
Type: arbitrary file write / remote code execution