include/global_session.php in Cacti 1.1.25 has XSS related to (1) the URI or (2) the refresh page.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1039569 | vdb entry third party advisory |
https://github.com/Cacti/cacti/issues/1010 | issue tracking patch exploit third party advisory |
https://github.com/Cacti/cacti/commit/93f661d8adcfa6618b11522cdab30e97bada33fd | third party advisory patch |