Sploitus

CVE-2024-25641

23 known exploits for CVE-2024-25641

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable through the "Package Import" feature, allows authenticated users having the "Import Templates" permission to execute arbitrary PHP code on the web server. The vulnerability is located within the `import_package()` function defined into the `/lib/import.php` script. The function blindly trusts the filename and file content provided within the XML data, and writes such files into the Cacti base path (or even outside, since path traversal sequences are not filtered). This can be exploited to write or overwrite arbitrary files on the web server, leading to execution of arbitrary PHP code or other security impacts. Version 1.2.27 contains a patch for this issue.

Affected products
Alt Linux, Cacti, Linuxmint, Ubuntu
Cacti
< 1.2.27
Fix
Available
CVSS 3.1
9.1 CRITICAL
EPSS
86.3% (100th percentile)
Weakness
CWE-20
NVD status
Modified
Published
2024-05-13
CVE-2024-25641 at NVD
Authoritative description, scoring and affected products

23 known exploits for CVE-2024-25641

Proof-of-concept code and exploit modules indexed by Sploitus

CVE-2024-25641
2026-08-29 KitPloitKITPLOIT
CVE-2024-25641---Cacti
2026-08-28 KitPloitKITPLOIT
CVE-2024-25641-CACTI-RCE-1.2.26
2026-08-28 KitPloitKITPLOIT
CVE-2024-25641-Exploit-for-Cacti-1.2.26
2026-08-27 KitPloitKITPLOIT
CVE-2024-25641
2026-08-27 KitPloitKITPLOIT
CVE-2024-25641
2026-08-26 KitPloitKITPLOIT
CVE-2024-25641-RCE-Automated-Exploit-Cacti-1.2.26
2026-08-26 KitPloitKITPLOIT
Exploit for SQL Injection in Dolibarr
2026-04-03 nekros1xxGITHUB
Exploit for Improper Input Validation in Cacti
2026-01-20 GabrielCF10GITHUB
Exploit for Code Injection in Xwiki
2025-08-09 D3ExtGITHUB
πŸ“„ Cacti 1.2.26 Remote Code Execution
2025-04-15 D3ExtPACKETSTORMPython
Cacti 1.2.26 - Remote Code Execution (RCE) (Authenticated)
2025-04-15 D3ExtEXPLOITDBPython
Exploit for Improper Input Validation in Cacti
2025-03-17 regantemudoGITHUB
Exploit for Improper Input Validation in Cacti
2024-11-22 XiaomingXGITHUB
Exploit for Improper Input Validation in Cacti
2024-08-29 StopThatTalaceGITHUB
Exploit for Improper Input Validation in Cacti
2024-08-27 SafarchandGITHUB
Exploit for Improper Input Validation in Cacti
2024-08-27 thisisveryfunnyGITHUB
Exploit for Improper Input Validation in Cacti
2024-08-26 5ma1lGITHUB
Cacti Import Packages Remote Code Execution
2024-06-13 EgiX, Christophe de la Fuente, metasploit.comPACKETSTORMRuby
Cacti Import Packages Remote Code Execution Exploit
2024-06-13 metasploitZDTRuby
Cacti 1.2.26 Remote Code Execution
2024-05-15 EgiX, karmainsecurity.comPACKETSTORM
Cacti 1.2.26 Remote Code Execution Vulnerability
2024-05-15 EgiXZDT
Cacti Import Packages RCE
2024-05-12 Egidio Romano, Christophe De La FuenteMETASPLOITRuby