PT-2023-5421 · Cacti+1 · Cacti+1

Vissamoutafis

·

Publicado

2023-09-06

·

Atualizado

2025-01-24

·

CVE-2023-39511

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cacti versions prior to 1.2.25
Description The issue is related to a Stored Cross-Site-Scripting (XSS) vulnerability, which allows an authenticated user to poison data stored in the Cacti database. This data will be viewed by administrative Cacti accounts and execute JavaScript code in the victim's browser at view-time. The script under reports admin.php displays reporting information about graphs, devices, data sources, etc. An adversary can deploy a stored XSS attack against any super user who has privileges of viewing the reports admin.php page by configuring a malicious device name related to a graph attached to a report. This configuration occurs through http://<HOST>/cacti/host.php, while the rendered malicious payload is exhibited at http://<HOST>/cacti/reports admin.php when a graph with the maliciously altered device name is linked to the report.
Recommendations For versions prior to 1.2.25, upgrade to version 1.2.25 or later to address the issue. As a temporary workaround for users unable to upgrade, manually filter HTML output. Restrict access to the reports admin.php page to minimize the risk of exploitation. Avoid using the http://<HOST>/cacti/host.php endpoint to configure device names until the issue is resolved. Consider temporarily disabling the reports admin.php script until a patch is available.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-7619
ALT-PU-2023-7621
ALT-PU-2024-7120
ALT-PU-2025-1813
BDU:2023-06051
CVE-2023-39511
GHSA-5HPR-4HHC-8Q42
OPENSUSE-SU-2023:0275-1
OPENSUSE-SU-2024:13203-1

Produtos afetados

Alt Linux
Cacti