CVE-2024-25641 is an arbitrary file write vulnerability in Cacti versions prior to 1.2.27, affecting Cacti, Fedora, and FedoraProject Cacti. Authenticated users with "Import Templates" permission can exploit the "Package Import" feature to write arbitrary files, including PHP code, onto the web server, leading to remote code execution. With a CVSS score of 7.2 (High) and an EPSS score of 0.88383, this vulnerability presents a significant risk, allowing attackers to achieve full compromise of the affected system. Exploit modules are publicly available in Metasploit and ExploitDB, indicating a high likelihood of exploitation, though community discussion and media coverage remain low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.27CPE matchmatch criteria | cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.