Cacti is an open source performance and fault management framework. The`consolenewsection` parameter is not properly sanitized when saving external links in links.php . Morever, the said consolenewsection parameter is stored in the database and reflected back to user in `index.php`, finally leading to stored XSS. Users with the privilege to create external links can manipulate the “consolenewsection” parameter in the http post request while creating external links to perform stored XSS attacks. The vulnerability known as XSS (Cross-Site Scripting) occurs when an application allows untrusted user input to be displayed on a web page without proper validation or escaping. This issue has been addressed in release version 1.2.28. All users are advised to upgrade. There are no known workarounds for this vulnerability.
History

Wed, 16 Oct 2024 19:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:cacti:cacti:1.2.27:*:*:*:*:*:*:*

Tue, 08 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Cacti
Cacti cacti
CPEs cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*
Vendors & Products Cacti
Cacti cacti
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Oct 2024 20:45:00 +0000

Type Values Removed Values Added
Description Cacti is an open source performance and fault management framework. The`consolenewsection` parameter is not properly sanitized when saving external links in links.php . Morever, the said consolenewsection parameter is stored in the database and reflected back to user in `index.php`, finally leading to stored XSS. Users with the privilege to create external links can manipulate the “consolenewsection” parameter in the http post request while creating external links to perform stored XSS attacks. The vulnerability known as XSS (Cross-Site Scripting) occurs when an application allows untrusted user input to be displayed on a web page without proper validation or escaping. This issue has been addressed in release version 1.2.28. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Title Stored Cross-site Scripting (XSS) when creating external links in Cacti
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-10-07T20:38:26.732Z

Updated: 2024-10-08T14:03:16.674Z

Reserved: 2024-08-09T14:23:55.512Z

Link: CVE-2024-43365

cve-icon Vulnrichment

Updated: 2024-10-08T13:57:57.008Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-07T21:15:16.247

Modified: 2024-10-16T19:15:56.007

Link: CVE-2024-43365

cve-icon Redhat

No data.