CVE-2021-23225Cross-site Scripting in Cacti

Severity
5.4MEDIUMNVD
EPSS
0.5%
top 34.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 19
Latest updateJan 20

Description

Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "new_username" field during creation of a new user via "Copy" method at user_admin.php.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages3 packages

debiandebian/cacti< cacti 1.2.1+ds1-1 (bookworm)
Debiancacti/cacti< 1.2.1+ds1-1+3
NVDcacti/cacti1.1.38

Also affects: Debian Linux 9.0

🔴Vulnerability Details

2
GHSA
GHSA-m54w-jgp2-mf5q: Cacti 12022-01-20
OSV
CVE-2021-23225: Cacti 12022-01-19

📋Vendor Advisories

1
Debian
CVE-2021-23225: cacti - Cacti 1.1.38 allows authenticated users with User Management permissions to inje...2021