PT-2022-9380 · Cacti · Cacti

Published

2022-01-19

·

Updated

2022-05-24

·

CVE-2021-23225

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cacti version 1.1.38
Description The issue allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the new username field during creation of a new user via the "Copy" method at the "user admin.php" endpoint.
Recommendations For Cacti version 1.1.38, consider restricting access to the "Copy" method in user admin.php to prevent exploitation until a fix is available. As a temporary workaround, avoid using the new username field for user creation until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23225
DLA-2965-1

Affected Products

Cacti