CVE-2018-20724 PUBLISHED

A cross-site scripting (XSS) vulnerability exists in pollers.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname for Data Collectors.

EPSS 0.58% · 68.8th percentile

Risk Scores

EPSS Score
0.58%
68.8th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTScacti0, 0.8.8b+dfsg-3, 0.8.8b+dfsg-5
Ubuntu:Pro:18.04:LTScacti0, 1.1.18+ds1-1, 1.1.27+ds1-2

Timeline

References

Open in Interactive Console →