Cacti Opensource Framework Vulnerable to Stored XSS Attacks
CVE-2024-43365

8.2HIGH

Key Information:

Vendor

Cacti

Status
Vendor
CVE Published:
7 October 2024

What is CVE-2024-43365?

Cacti, an open source performance and fault management framework, is susceptible to a stored XSS vulnerability due to the improper sanitization of the consolenewsection parameter in the links.php file. This parameter, when manipulated by users with the privilege to create external links, allows malicious scripts to be saved in the database and subsequently reflected back to users in index.php. This can lead to significant security risks as untrusted input is displayed on web pages without adequate validation or escaping. Users are strongly encouraged to upgrade to version 1.2.28 or later to mitigate this vulnerability, as no workarounds currently exist to address the issue.

Affected Version(s)

cacti < 1.2.28

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.
CVE-2024-43365 : Cacti Opensource Framework Vulnerable to Stored XSS Attacks