CVE-2020-7106 PUBLISHED

Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS).

EPSS 4.09% · 88.5th percentile

Risk Scores

EPSS Score
4.09%
88.5th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTScacti0.8.8f+ds1-4ubuntu4.16.04, 0.8.8f+ds1-4ubuntu4.16.04.1, 0.8.8f+ds1-4ubuntu4.16.04.2
Ubuntu:Pro:14.04:LTScacti0, 0.8.8b+dfsg-3, 0.8.8b+dfsg-5
Ubuntu:Pro:18.04:LTScacti0, 1.1.18+ds1-1, 1.1.27+ds1-2

Timeline

References

Open in Interactive Console →