CVE-2017-15194

MEDIUM

Cacti - XSS

Title source: rule

Description

include/global_session.php in Cacti 1.1.25 has XSS related to (1) the URI or (2) the refresh page.

Scores

CVSS v3 6.1
EPSS 0.0031
EPSS Percentile 53.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Classification

CWE
CWE-79
Status draft

Affected Products (1)

cacti/cacti

Timeline

Published Oct 11, 2017
Tracked Since Feb 18, 2026