lib/rrd.php in Cacti 1.1.27 allows remote authenticated administrators to execute arbitrary OS commands via the path_rrdtool parameter in an action=save request to settings.php.
2017-11-07T20:29:00.183
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 7.2 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0