USN-7226-1

Advisory lineage Upstream: 2 Downstream: 0
Published: 23 Jan 2025, 14:27
Last modified:27 Apr 2026, 17:41

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 Jan 2025, 14:27
Published
Vulnerability first disclosed
27 Apr 2026, 17:41
Last Modified
Vulnerability information updated

Description

cacti vulnerability It was discovered that Cacti did not properly sanitize the 'poller_id' parameter in the "remote_agent.php" file. A remote attacker could possibly use this issue to achieve remote code execution.

Affected Systems

  • ubuntucacti

    < 1.1.38+ds1-1ubuntu0.1~esm4 | < 1.2.10+ds1-1ubuntu1.1+esm2 | < 1.2.19+ds1-2ubuntu1.1+esm2

References (2)