PT-2017-11788 · Cacti · Cacti

Kimiizhang

·

Publicado

2017-07-10

·

Atualizado

2024-06-15

·

CVE-2017-11163

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cacti version 1.1.12
Description A cross-site scripting (XSS) issue exists, allowing remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the cancel url variable.
Recommendations For Cacti version 1.1.12, update to a version that fixes this issue, ensuring that the cancel url variable is properly sanitized to prevent XSS attacks.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-11163
MGASA-2017-0267
OPENSUSE-SU-2024:10670-1

Produtos afetados

Cacti