We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)
Ok

THREATINT
PUBLISHED

CVE-2024-27082

Cacti Cross-site Scripting vulnerability when managing trees

Reserved:2024-02-19
Published:2024-05-13
Updated:2024-05-13

Description

Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 are vulnerable to stored cross-site scripting, a type of cross-site scripting where malicious scripts are permanently stored on a target server and served to users who access a particular page. Version 1.2.27 contains a patch for the issue.



HIGH: 7.6CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

< 1.2.27
affected

References

https://github.com/Cacti/cacti/security/advisories/GHSA-j868-7vjp-rp9h

cve.org CVE-2024-27082

nvd.nist.gov CVE-2024-27082

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-27082