CVE-2023-49086

CVSS v3.1 5.4 (Medium)
54% Progress
EPSS 0.06 % (24th)
0.06% Progress
Affected Products 1
Advisories 4
NVD Status Modified

Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). A vulnerability in versions prior to 1.2.27 bypasses an earlier fix for CVE-2023-39360, therefore leading to a DOM XSS attack. Exploitation of the vulnerability is possible for an authorized user. The vulnerable component is the graphs_new.php. The impact of the vulnerability is execution of arbitrary JavaScript code in the attacked user's browser. This issue has been patched in version 1.2.27.

Weaknesses
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Related CVEs
CVE Status
PUBLISHED
NVD Status
Modified
CNA
GitHub, Inc.
Published Date
2023-12-22 00:15:34
(9 months ago)
Updated Date
2024-06-10 17:16:15
(3 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Cacti 1.2.25 cpe:2.3:a:cacti:cacti:1.2.25
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...