HTTP: Cacti Group Cacti graph_templates_inputs.php column_name SQL Injection
This signature detects attempts to exploit a known vulnerability against Cacti. A successful attack can lead to command injection and arbitrary code execution.
Extended Description
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `form_save()` function in `graph_template_inputs.php` is not thoroughly checked and is used to concatenate the SQL statement in `draw_nontemplated_fields_graph_item()` function from `lib/html_form_templates.php` , finally resulting in SQL injection. Version 1.2.27 contains a patch for the issue.
Affected Products
Fedoraproject fedora
References
CVE: CVE-2024-31458
URL: https://github.com/Cacti/cacti/security/advisories/GHSA-jrxg-8wh8-943x
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Cacti
Fedoraproject