ZeroHour

CVE-2019-11025

PoC
CVSS 3.1
5.4 medium
EPSS
1%p69
Published
()
Modified
Description

In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options) in the View poller cache, leading to XSS.

Vendors
cactidebian
Products
cacti, debian linux
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.