PT-2017-11647 · Cacti · Cacti
Kimiizhang
+1
·
Published
2017-07-06
·
Updated
2024-06-15
·
CVE-2017-10970
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Cacti version 1.1.12
Description
A cross-site scripting (XSS) issue exists, allowing remote anonymous users to inject arbitrary web script or HTML. This is related to the
die html input error function in lib/html validate.php and is exploited via the id parameter in link.php.Recommendations
For Cacti version 1.1.12, consider restricting access to the
link.php file until a patch is available, and avoid using the id parameter in this context to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cacti