ZeroHour

CVE-2018-20726

PoC
CVSS 3.0
5.4 medium
EPSS
1%p62
Published
()
Modified
Description

A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname field for Devices.

Vendors
cacti
Products
cacti
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.