CVE-2018-20723 PUBLISHED

A cross-site scripting (XSS) vulnerability exists in color_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Name field for a Color.

EPSS 0.50% · 65.6th percentile

Risk Scores

EPSS Score
0.50%
65.6th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTScacti0, 0.8.8b+dfsg-3, 0.8.8b+dfsg-5
Ubuntu:Pro:16.04:LTScacti0, 0.8.8f+ds1-2, 0.8.8f+ds1-3
Ubuntu:Pro:18.04:LTScacti0, 1.1.18+ds1-1, 1.1.27+ds1-2

Timeline

References

Open in Interactive Console →