Reflected Cross Site Scripting (XSS) vulnerability in Cacti v1.2.25, allows remote attackers to escalate privileges when uploading an xml template file via templates_import.php.
References
Link | Resource |
---|---|
https://gist.github.com/ISHGARD-2/a6b57de899f977e2af41780e7428b4bf | Exploit Third Party Advisory |
https://github.com/Cacti/cacti/security/advisories/GHSA-xwqc-7jc4-xm73 | Exploit Vendor Advisory |
Configurations
History
No history.
Information
Published : 2023-12-22 11:15
Updated : 2023-12-29 06:23
NVD link : CVE-2023-50569
Mitre link : CVE-2023-50569
CVE.ORG link : CVE-2023-50569
JSON object : View
Products Affected
cacti
- cacti
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')