{"id":56842,"date":"2024-05-15T18:39:44","date_gmt":"2024-05-15T14:39:44","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/178584\/KIS-2024-04.txt"},"modified":"2024-05-15T18:39:44","modified_gmt":"2024-05-15T14:39:44","slug":"cacti-1-2-26-remote-code-execution","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cacti-1-2-26-remote-code-execution\/","title":{"rendered":"Cacti 1.2.26 Remote Code Execution"},"content":{"rendered":"<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>Cacti &lt;= 1.2.26 (import.php) Remote Code Execution Vulnerability<br \/>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/p>\n[-] Software Link:<\/p>\n<p>https:\/\/cacti.net<\/p>\n[-] Affected Versions:<\/p>\n<p>Version 1.2.26 and prior versions.<\/p>\n[-] Vulnerability Description:<\/p>\n<p>The vulnerability is located within the &#8220;import_package()&#8221; function<br \/>defined into the \/lib\/import.php script. This function blindly trusts<br \/>the filename and file content provided within the uploaded XML data,<br \/>and writes such files into the Cacti base path (or even outside, since<br \/>Path Traversal sequences are not filtered). This can be exploited to<br \/>write or overwrite arbitrary files on the web server, leading to<br \/>execution of arbitrary PHP code or other security impacts.<\/p>\n<p>Successful exploitation of this vulnerability requires an user account<br \/>having the &#8220;Import Templates&#8221; permission.<\/p>\n[-] Solution:<\/p>\n<p>Upgrade to version 1.2.27 or later.<\/p>\n[-] Disclosure Timeline:<\/p>\n[17\/01\/2024] &#8211; Vendor notified through GitHub<br \/>[12\/05\/2024] &#8211; Version 1.2.27 released<br \/>[13\/05\/2024] &#8211; Publication of this advisory<\/p>\n[-] CVE Reference:<\/p>\n<p>The Common Vulnerabilities and Exposures project (cve.mitre.org) has<br \/>assigned the name CVE-2024-25641 to this vulnerability.<\/p>\n[-] Credits:<\/p>\n<p>Vulnerability discovered by Egidio Romano.<\/p>\n[-] Other References:<\/p>\n<p>https:\/\/github.com\/Cacti\/cacti\/security\/advisories\/GHSA-7cmj-g5qc-pj88<\/p>\n[-] Original Advisory:<\/p>\n<p>https:\/\/karmainsecurity.com\/KIS-2024-04<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-Cacti &lt;= 1.2.26 (import.php) Remote Code Execution Vulnerability&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;- [-] Software Link: https:\/\/cacti.net [-] Affected Versions: Version 1.2.26 and prior versions. [-] Vulnerability Description: The vulnerability is located within the &#8220;import_package()&#8221; functiondefined into the \/lib\/import.php script. This function blindly truststhe filename and file content provided within the uploaded XML data,and writes such files into the Cacti &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-56842","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/56842","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=56842"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/56842\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=56842"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=56842"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=56842"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}