CVE-2024-27082Cross-site Scripting in Cacti

Severity
5.4MEDIUMNVD
EPSS
0.4%
top 41.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 14

Description

Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 are vulnerable to stored cross-site scripting, a type of cross-site scripting where malicious scripts are permanently stored on a target server and served to users who access a particular page. Version 1.2.27 contains a patch for the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages3 packages

NVDcacti/cacti< 1.2.27
debiandebian/cacti< cacti 1.2.24+ds1-1+deb12u5 (bookworm)
Debiancacti/cacti< 1.2.24+ds1-1+deb12u5+2

🔴Vulnerability Details

1
OSV
CVE-2024-27082: Cacti provides an operational monitoring and fault management framework2024-05-14

📋Vendor Advisories

1
Debian
CVE-2024-27082: cacti - Cacti provides an operational monitoring and fault management framework. Version...2024