Cacti is an open source performance and fault management framework. The `fileurl` parameter is not properly sanitized when saving external links in `links.php` . Morever, the said fileurl is placed in some html code which is passed to the `print` function in `link.php` and `index.php`, finally leading to stored XSS. Users with the privilege to create external links can manipulate the `fileurl` parameter in the http post request while creating external links to perform stored XSS attacks. The vulnerability known as XSS (Cross-Site Scripting) occurs when an application allows untrusted user input to be displayed on a web page without proper validation or escaping. This issue has been addressed in release version 1.2.28. All users are advised to upgrade. There are no known workarounds for this issue.
History

Tue, 08 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Cacti
Cacti cacti
CPEs cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*
Vendors & Products Cacti
Cacti cacti
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Oct 2024 20:45:00 +0000

Type Values Removed Values Added
Description Cacti is an open source performance and fault management framework. The `fileurl` parameter is not properly sanitized when saving external links in `links.php` . Morever, the said fileurl is placed in some html code which is passed to the `print` function in `link.php` and `index.php`, finally leading to stored XSS. Users with the privilege to create external links can manipulate the `fileurl` parameter in the http post request while creating external links to perform stored XSS attacks. The vulnerability known as XSS (Cross-Site Scripting) occurs when an application allows untrusted user input to be displayed on a web page without proper validation or escaping. This issue has been addressed in release version 1.2.28. All users are advised to upgrade. There are no known workarounds for this issue.
Title Stored Cross-site Scripting (XSS) when creating external links in Cacti
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-10-07T20:34:58.936Z

Updated: 2024-10-08T13:53:28.987Z

Reserved: 2024-08-09T14:23:55.512Z

Link: CVE-2024-43362

cve-icon Vulnrichment

Updated: 2024-10-08T13:08:16.556Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-07T21:15:15.470

Modified: 2024-10-17T18:14:33.337

Link: CVE-2024-43362

cve-icon Redhat

No data.