CVE-2018-20726

MEDIUM

Cacti < 1.2.0 - Stored Cross-Site Scripting via Website Hostname Field

Title source: llm
STIX 2.1

Description

A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname field for Devices.

References (7)

Core 7
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/Cacti/cacti/blob/develop/CHANGELOG
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/Cacti/cacti/issues/2213

Scores

CVSS v3 5.4
EPSS 0.0104
EPSS Percentile 59.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
cacti/cacti < 1.2.0
Published Jan 16, 2019
Tracked Since Feb 18, 2026