DEBIAN-CVE-2025-24368

Source
https://security-tracker.debian.org/tracker/DEBIAN-CVE-2025-24368
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-24368.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2025-24368
Upstream
Published
2025-01-27T18:15:42Z
Modified
2025-09-19T07:34:30.227424Z
Summary
[none]
Details

Cacti is an open source performance and fault management framework. Some of the data stored in automationtreerules.php is not thoroughly checked and is used to concatenate the SQL statement in buildruleitemfilter() function from lib/apiautomation.php, resulting in SQL injection. This vulnerability is fixed in 1.2.29.

References

Affected packages

Debian:11 / cacti

Package

Name
cacti
Purl
pkg:deb/debian/cacti?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.16+ds1-2+deb11u5

Affected versions

1.*

1.2.16+ds1-2
1.2.16+ds1-2+deb11u1
1.2.16+ds1-2+deb11u2
1.2.16+ds1-2+deb11u3
1.2.16+ds1-2+deb11u4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / cacti

Package

Name
cacti
Purl
pkg:deb/debian/cacti?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.24+ds1-1+deb12u5

Affected versions

1.*

1.2.24+ds1-1
1.2.24+ds1-1+deb12u1
1.2.24+ds1-1+deb12u2
1.2.24+ds1-1+deb12u3
1.2.24+ds1-1+deb12u4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / cacti

Package

Name
cacti
Purl
pkg:deb/debian/cacti?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.28+ds1-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / cacti

Package

Name
cacti
Purl
pkg:deb/debian/cacti?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.28+ds1-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}