CVE-2023-50250
published 2023-12-22CVE-2023-50250: Cacti is an open source operational monitoring and fault management framework. A reflection cross-site scripting vulnerability was discovered in version…
PriorityP428medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.28%
67.0th percentile
Cacti is an open source operational monitoring and fault management framework. A reflection cross-site scripting vulnerability was discovered in version 1.2.25. Attackers can exploit this vulnerability to perform actions on behalf of other users. The vulnerability is found in `templates_import.php.` When uploading an xml template file, if the XML file does not pass the check, the server will give a JavaScript pop-up prompt, which contains unfiltered xml template file name, resulting in XSS. An attacker exploiting this vulnerability could execute actions on behalf of other users. This ability to impersonate users could lead to unauthorized changes to settings. As of time of publication, no patched versions are available.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cacti | cacti | < 1.2.27 | 1.2.27 |
| cacti | cacti | < 1.2.27 | 1.2.27 |
| cacti | cacti | — | — |
| cacti | cacti | >= 0 < 1.2.24+ds1-1+deb12u2 | 1.2.24+ds1-1+deb12u2 |
| cacti | cacti | >= 0 < 1.2.24+ds1-1+deb12u3 | 1.2.24+ds1-1+deb12u3 |
| cacti | cacti | >= 0 < 1.2.26+ds1-1 | 1.2.26+ds1-1 |
| cacti | cacti | >= 0 < 1.2.27+ds1-1 | 1.2.27+ds1-1 |
| cacti | cacti | >= 0 < 1.2.26+ds1-1 | 1.2.26+ds1-1 |
| cacti | cacti | >= 0 < 1.2.27+ds1-1 | 1.2.27+ds1-1 |
| debian | cacti | < cacti 1.2.24+ds1-1+deb12u2 (bookworm) | cacti 1.2.24+ds1-1+deb12u2 (bookworm) |
| debian | cacti | < cacti 1.2.24+ds1-1+deb12u3 (bookworm) | cacti 1.2.24+ds1-1+deb12u3 (bookworm) |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM
vendor_debian5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-29894: Cacti provides an operational monitoring and fault management framework
osv·2024-05-14·CVSS 6.1
CVE-2024-29894 [MEDIUM] CVE-2024-29894: Cacti provides an operational monitoring and fault management framework
Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a residual cross-site scripting vulnerability caused by an incomplete fix for CVE-2023-50250. `raise_message_javascript` from `lib/functions.php` now uses purify.js to fix CVE-2023-50250 (among others). However, it still generates the code out of unescaped PHP variables `$title` and `$header`. If those variables contain single quotes, they can be used to inject JavaScript code. An attacker exploiting this vulnerability could execute actions on behalf of other users. This ability to impersonate users could lead to unauthorized changes to settings. Version 1.2.27 fixes this issue.
OSV
CVE-2023-50250: Cacti is an open source operational monitoring and fault management framework
osv·2023-12-22·CVSS 6.1
CVE-2023-50250 [MEDIUM] CVE-2023-50250: Cacti is an open source operational monitoring and fault management framework
Cacti is an open source operational monitoring and fault management framework. A reflection cross-site scripting vulnerability was discovered in version 1.2.25. Attackers can exploit this vulnerability to perform actions on behalf of other users. The vulnerability is found in `templates_import.php.` When uploading an xml template file, if the XML file does not pass the check, the server will give a JavaScript pop-up prompt, which contains unfiltered xml template file name, resulting in XSS. An attacker exploiting this vulnerability could execute actions on behalf of other users. This ability to impersonate users could lead to unauthorized changes to settings. As of time of publication, no patched versions are available.
Debian
CVE-2024-29894: cacti - Cacti provides an operational monitoring and fault management framework. Version...
vendor_debian·2024·CVSS 5.4
CVE-2024-29894 [MEDIUM] CVE-2024-29894: cacti - Cacti provides an operational monitoring and fault management framework. Version...
Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a residual cross-site scripting vulnerability caused by an incomplete fix for CVE-2023-50250. `raise_message_javascript` from `lib/functions.php` now uses purify.js to fix CVE-2023-50250 (among others). However, it still generates the code out of unescaped PHP variables `$title` and `$header`. If those variables contain single quotes, they can be used to inject JavaScript code. An attacker exploiting this vulnerability could execute actions on behalf of other users. This ability to impersonate users could lead to unauthorized changes to settings. Version 1.2.27 fixes this issue.
Scope: local
bookworm: resolved (fixed in 1.2.24+ds1-1+deb12u3)
bullseye: resolved
forky: resolved
Debian
CVE-2023-50250: cacti - Cacti is an open source operational monitoring and fault management framework. A...
vendor_debian·2023·CVSS 5.4
CVE-2023-50250 [MEDIUM] CVE-2023-50250: cacti - Cacti is an open source operational monitoring and fault management framework. A...
Cacti is an open source operational monitoring and fault management framework. A reflection cross-site scripting vulnerability was discovered in version 1.2.25. Attackers can exploit this vulnerability to perform actions on behalf of other users. The vulnerability is found in `templates_import.php.` When uploading an xml template file, if the XML file does not pass the check, the server will give a JavaScript pop-up prompt, which contains unfiltered xml template file name, resulting in XSS. An attacker exploiting this vulnerability could execute actions on behalf of other users. This ability to impersonate users could lead to unauthorized changes to settings. As of time of publication, no patched versions are available.
Scope: local
bookworm: resolved (fixed in 1.2.24+ds1-1+deb12u2)
bullse
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/Cacti/cacti/blob/5f6f65c215d663a775950b2d9db35edbaf07d680/templates_import.phphttps://github.com/Cacti/cacti/security/advisories/GHSA-xwqc-7jc4-xm73https://lists.fedoraproject.org/archives/list/[email protected]/message/RBEOAFKRARQHTDIYSL723XAFJ2Q6624X/https://github.com/Cacti/cacti/blob/5f6f65c215d663a775950b2d9db35edbaf07d680/templates_import.phphttps://github.com/Cacti/cacti/security/advisories/GHSA-xwqc-7jc4-xm73https://lists.fedoraproject.org/archives/list/[email protected]/message/RBEOAFKRARQHTDIYSL723XAFJ2Q6624X/
2023-12-22
Published