Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-20725

Опубликовано: 16 янв. 2019
Источник: debian

Описание

A cross-site scripting (XSS) vulnerability exists in graph_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Graph Vertical Label.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cactifixed1.2.1+ds1-1package
cactinot-affectedstretchpackage
cactinot-affectedjessiepackage

Примечания

  • https://github.com/Cacti/cacti/commit/80c2a88fb2afb93f87703ba4641f9970478c102d

  • https://github.com/Cacti/cacti/issues/2214

  • Introduced by https://github.com/Cacti/cacti/commit/94bcc756a15c9fc1b6595386e1d37ba5b08df4ec (v1.0)

Связанные уязвимости

CVSS3: 4.8
ubuntu
около 7 лет назад

A cross-site scripting (XSS) vulnerability exists in graph_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Graph Vertical Label.

CVSS3: 4.8
nvd
около 7 лет назад

A cross-site scripting (XSS) vulnerability exists in graph_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Graph Vertical Label.

CVSS3: 4.8
github
больше 3 лет назад

A cross-site scripting (XSS) vulnerability exists in graph_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Graph Vertical Label.

suse-cvrf
почти 6 лет назад

Security update for cacti, cacti-spine

suse-cvrf
почти 6 лет назад

Security update for cacti, cacti-spine