Loading
Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29.
Use CWE-144, Cacti vendor hub and Cacti product page to widen CVE-2025-24367 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-22604, CVE-2005-10004 and CVE-2025-26520 for nearby disclosures in the same product family.