Cacti is an open source performance and fault management framework. Some of the data stored in automation_tree_rules.php is not thoroughly checked and is used to concatenate the SQL statement in build_rule_item_filter() function from lib/api_automation.php, resulting in SQL injection. This vulnerability is fixed in 1.2.29.
- https://github.com/Cacti/cacti/security/advisories/GHSA-f9c7-7rc3-574c
- https://github.com/fkie-cad/nvd-json-data-feeds
- https://github.com/w4zu/Debian_security