ALT-PU-2019-1595-1
Closed vulnerabilities
Published: 2019-04-09
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2019-11025
In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options) in the View poller cache, leading to XSS.
Severity: MEDIUM (5.4)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
References:
- https://github.com/Cacti/cacti/compare/6ea486a...99995bb
- https://github.com/Cacti/cacti/compare/6ea486a...99995bb
- https://github.com/Cacti/cacti/issues/2581
- https://github.com/Cacti/cacti/issues/2581
- [debian-lts-announce] 20190416 [SECURITY] [DLA 1757-1] cacti security update
- [debian-lts-announce] 20190416 [SECURITY] [DLA 1757-1] cacti security update
- [debian-lts-announce] 20220329 [SECURITY] [DLA 2965-1] cacti security update
- [debian-lts-announce] 20220329 [SECURITY] [DLA 2965-1] cacti security update