CVE-2021-3816Cross-site Scripting in Cacti

Severity
5.4MEDIUMNVD
EPSS
0.3%
top 50.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 19
Latest updateJan 20

Description

Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary HTML in the group_prefix field during the creation of a new group via "Copy" method at user_group_admin.php.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages3 packages

debiandebian/cacti< cacti 1.2.1+ds1-1 (bookworm)
Debiancacti/cacti< 1.2.1+ds1-1+3
NVDcacti/cacti1.1.38

🔴Vulnerability Details

2
GHSA
GHSA-6gq5-766m-4c86: Cacti 12022-01-20
OSV
CVE-2021-3816: Cacti 12022-01-19

📋Vendor Advisories

1
Debian
CVE-2021-3816: cacti - Cacti 1.1.38 allows authenticated users with User Management permissions to inje...2021