CVE-2023-49086
CVSS v3.1
5.4 (Medium)
EPSS
0.06 % (24th)
Affected Products
1
Advisories
4
NVD Status
Modified
Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). A vulnerability in versions prior to 1.2.27 bypasses an earlier fix for CVE-2023-39360, therefore leading to a DOM XSS attack. Exploitation of the vulnerability is possible for an authorized user. The vulnerable component is the graphs_new.php
. The impact of the vulnerability is execution of arbitrary JavaScript code in the attacked user's browser. This issue has been patched in version 1.2.27.
Weaknesses
- CWE-79
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Related CVEs
- CVE Status
- PUBLISHED
- NVD Status
- Modified
- CNA
- GitHub, Inc.
- Published Date
-
2023-12-22 00:15:34
(9 months ago) - Updated Date
-
2024-06-10 17:16:15
(3 months ago)
Affected Products
Loading...
Loading...
Loading...
Configuration #1
|
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...