CVE-2020-25706 PUBLISHED

A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti 1.2.13) due to Improper escaping of error message during template import preview in the xml_path field

EPSS 1.46% · 80.7th percentile

Risk Scores

EPSS Score
1.46%
80.7th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTScacti0, 0.8.8b+dfsg-3, 0.8.8b+dfsg-5
Ubuntu:Pro:20.04:LTScacti1.2.10+ds1-1ubuntu1.1+esm2, 0, 1.2.4+ds1-2ubuntu3
Ubuntu:Pro:18.04:LTScacti1.1.38+ds1-1ubuntu0.1~esm3, 1.1.38+ds1-1ubuntu0.1~esm4, 0

Timeline

References

Open in Interactive Console →