First published: Wed Feb 12 2025(Updated: )
Cacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template parameter. NOTE: this issue exists because of an incomplete fix for CVE-2024-54146.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cacti | <=1.2.29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26520 has a medium severity due to the potential for SQL injection exploits.
To fix CVE-2025-26520, upgrade to Cacti version 1.2.30 or later which addresses the vulnerability.
The impact of CVE-2025-26520 can allow attackers to execute arbitrary SQL code in the database.
CVE-2025-26520 affects users of Cacti versions up to and including 1.2.29.
CVE-2025-26520 was discovered as a result of incomplete fixes related to a prior vulnerability, CVE-2024-54146.