PT-2021-9727 · Cacti+4 · Cacti+4

Netniv

·

Published

2021-07-17

·

Updated

2025-01-24

·

CVE-2020-14424

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cacti versions prior to 1.2.18
Description The issue allows remote attackers to trigger XSS via template import for the midwinter theme. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations For versions prior to 1.2.18, update to version 1.2.18 or later to resolve the issue. As a temporary workaround, consider restricting access to the template import feature for the midwinter theme until a patch is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2264
ALT-PU-2025-1813
CVE-2020-14424
OPENSUSE-SU-2021:1190-1
OPENSUSE-SU-2021:1208-1
OPENSUSE-SU-2021_1190-1
OPENSUSE-SU-2024:10670-1
USN-5214-1

Affected Products

Alt Linux
Cacti
Linuxmint
Suse
Ubuntu