Skip to content

feature: cacti - CVE-2024-25641 - arbitrary file write via package import (authenticated RCE) #124

@hyde-repo

Description

@hyde-repo

Add CVE-2024-25641 to the inventory.

Authenticated users with "Import Templates" permission can craft a malicious package that abuses the template import feature to perform arbitrary file writes. This allows execution of PHP code on the server by placing files under the web root.

Section: ctf/monitoring/cacti/
Type: arbitrary file write / remote code execution

Metadata

Metadata

Assignees

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions