Cacti Opensource Framework Vulnerable to Stored XSS Attacks
CVE-2024-43365
8.2HIGH
What is CVE-2024-43365?
Cacti, an open source performance and fault management framework, is susceptible to a stored XSS vulnerability due to the improper sanitization of the consolenewsection
parameter in the links.php file. This parameter, when manipulated by users with the privilege to create external links, allows malicious scripts to be saved in the database and subsequently reflected back to users in index.php. This can lead to significant security risks as untrusted input is displayed on web pages without adequate validation or escaping. Users are strongly encouraged to upgrade to version 1.2.28 or later to mitigate this vulnerability, as no workarounds currently exist to address the issue.
Affected Version(s)
cacti < 1.2.28