Multiple Cross Site Scripting (XSS) vulneratiblities exist in Cacti 1.2.12 in (1) reports_admin.php, (2) data_queries.php, (3) data_input.php, (4) graph_templates.php, (5) graphs.php, (6) reports_admin.php, and (7) data_input.php.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/Cacti/cacti/issues/3549 | issue tracking exploit third party advisory |
https://lists.debian.org/debian-lts-announce/2022/03/msg00038.html | third party advisory mailing list |
https://lists.debian.org/debian-lts-announce/2022/12/msg00039.html | third party advisory mailing list |