Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS).
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2069-1 cacti security update
Debian DLA Debian DLA DLA-2965-1 cacti security update
EUVD EUVD EUVD-2020-28240 Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS).
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T09:18:03.119Z

Reserved: 2020-01-16T00:00:00

Link: CVE-2020-7106

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-01-16T04:15:11.697

Modified: 2024-11-21T05:36:38.350

Link: CVE-2020-7106

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses