PT-2017-11788 · Cacti · Cacti

Kimiizhang

·

Published

2017-07-10

·

Updated

2024-06-15

·

CVE-2017-11163

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cacti version 1.1.12
Description A cross-site scripting (XSS) issue exists, allowing remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the cancel url variable.
Recommendations For Cacti version 1.1.12, update to a version that fixes this issue, ensuring that the cancel url variable is properly sanitized to prevent XSS attacks.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-11163
MGASA-2017-0267
OPENSUSE-SU-2024:10670-1

Affected Products

Cacti