CVE-2017-12978Cross-site Scripting in Cacti

Severity
5.4MEDIUMNVD
EPSS
0.3%
top 43.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 21
Latest updateMay 17

Description

lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages3 packages

debiandebian/cacti< cacti 1.1.18+ds1-1 (bookworm)
Debiancacti/cacti< 1.1.18+ds1-1+3
NVDcacti/cacti1.1.17

Patches

🔴Vulnerability Details

2
GHSA
GHSA-385c-m8p7-qvr3: lib/html2022-05-17
OSV
CVE-2017-12978: lib/html2017-08-21

📋Vendor Advisories

1
Debian
CVE-2017-12978: cacti - lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external l...2017

💬Community

3
Bugzilla
CVE-2017-12927 CVE-2017-12978 cacti: various flaws [epel-all]2017-08-24
Bugzilla
CVE-2017-12927 CVE-2017-12978 cacti: various flaws [fedora-all]2017-08-24
Bugzilla
CVE-2017-12978 cacti: cross-site scripting vulnerability in lib/html.php2017-08-24