CVE-2013-5588Cross-site Scripting in Cacti

Severity
4.3MEDIUMNVD
EPSS
0.3%
top 44.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 29
Latest updateMay 14

Description

Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the step parameter to install/index.php or (2) the id parameter to cacti/host.php.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages4 packages

debiandebian/cacti< cacti 0.8.8b+dfsg-3 (bookworm)
Debiancacti/cacti< 0.8.8b+dfsg-3+3
NVDcacti/cacti0.8.8b+33
NVDopensuse/opensuse13.1, 13.2+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5r75-j6jg-x3cp: Multiple cross-site scripting (XSS) vulnerabilities in Cacti 02022-05-14
OSV
CVE-2013-5588: Multiple cross-site scripting (XSS) vulnerabilities in Cacti 02013-08-29

📋Vendor Advisories

1
Debian
CVE-2013-5588: cacti - Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b and earlier ...2013

💬Community

3
Bugzilla
CVE-2013-5588 CVE-2013-5589 cacti: XSS and SQL injection flaws2013-08-26
Bugzilla
CVE-2013-5589 CVE-2013-5588 cacti: XSS and SQL injection flaws [epel-all]2013-08-26
Bugzilla
CVE-2013-5589 CVE-2013-5588 cacti: XSS and SQL injection flaws [fedora-all]2013-08-26