lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/Cacti/cacti/commit/9c610a7a4e29595dcaf7d7082134e4b89619ea24 | issue tracking third party advisory patch |
http://www.securitytracker.com/id/1039226 | vdb entry |
https://github.com/Cacti/cacti/issues/918 | issue tracking third party advisory patch |
https://github.com/Cacti/cacti/blob/develop/docs/CHANGELOG | issue tracking third party advisory patch |