Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-23225

Опубликовано: 19 янв. 2022
Источник: debian

Описание

Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "new_username" field during creation of a new user via "Copy" method at user_admin.php.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cactifixed1.2.1+ds1-1package

Примечания

  • https://github.com/Cacti/cacti/issues/1882

  • overlap with CVE-2020-7106 (registered earlier, but issue above is from 2018) which refactors user_admin.php XSS protection

  • input (not output) validation not addressed, malicious username still can be created after fix

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 4 лет назад

Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "new_username" field during creation of a new user via "Copy" method at user_admin.php.

CVSS3: 5.4
nvd
около 4 лет назад

Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "new_username" field during creation of a new user via "Copy" method at user_admin.php.

CVSS3: 5.4
github
около 4 лет назад

Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "new_username" field during creation of a new user via "Copy" method at user_admin.php.