CVE-2024-31443Cross-site Scripting in Cacti

Severity
5.4MEDIUMNVD
CNA5.7
EPSS
0.5%
top 34.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 14
Latest updateAug 20

Description

Cacti provides an operational monitoring and fault management framework. Prior to 1.2.27, some of the data stored in `form_save()` function in `data_queries.php` is not thoroughly checked and is used to concatenate the HTML statement in `grow_right_pane_tree()` function from `lib/html.php` , finally resulting in cross-site scripting. Version 1.2.27 contains a patch for the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages3 packages

CVEListV5cacti/cacti< 1.2.27
NVDcacti/cacti< 1.2.27
Debiancacti/cacti< 1.2.16+ds1-2+deb11u4+3

Also affects: Fedora 39

Patches

🔴Vulnerability Details

2
OSV
CVE-2024-31443: Cacti provides an operational monitoring and fault management framework2024-05-14
CVEList
Cacti XSS vulnerability in lib/html_tree.php by reading dirty data stored in database2024-05-13

📋Vendor Advisories

2
Ubuntu
Cacti vulnerabilities2024-08-20
Debian
CVE-2024-31443: cacti - Cacti provides an operational monitoring and fault management framework. Prior t...2024
CVE-2024-31443 — Cross-site Scripting in Cacti | cvebase