27Oca
CVE-2025-24368 | Cacti up to 1.2.28 automation_tree_rules.php build_rule_item_filter sql injection
A vulnerability, which was classified as critical, was found in Cacti up to 1.2.28. This affects the functionbuild_rule_item_filter
in the library lib/api_automation.php of the file automation_tree_rules.php. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-24368. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.