Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-20723

Опубликовано: 16 янв. 2019
Источник: debian

Описание

A cross-site scripting (XSS) vulnerability exists in color_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Name field for a Color.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cactifixed1.2.1+ds1-1package
cactinot-affectedstretchpackage
cactinot-affectedjessiepackage

Примечания

  • https://github.com/Cacti/cacti/commit/80c2a88fb2afb93f87703ba4641f9970478c102d

  • https://github.com/Cacti/cacti/issues/2215

Связанные уязвимости

CVSS3: 4.8
ubuntu
около 7 лет назад

A cross-site scripting (XSS) vulnerability exists in color_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Name field for a Color.

CVSS3: 4.8
nvd
около 7 лет назад

A cross-site scripting (XSS) vulnerability exists in color_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Name field for a Color.

CVSS3: 4.8
github
больше 3 лет назад

A cross-site scripting (XSS) vulnerability exists in color_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Name field for a Color.

suse-cvrf
почти 6 лет назад

Security update for cacti, cacti-spine

suse-cvrf
почти 6 лет назад

Security update for cacti, cacti-spine