CVE-2019-11025

MEDIUM

Cacti < 1.2.3 - Stored Cross-Site Scripting via SNMP Community String

Title source: llm
STIX 2.1

Description

In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options) in the View poller cache, leading to XSS.

References (4)

Core 4
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/Cacti/cacti/issues/2581
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/Cacti/cacti/compare/6ea486a...99995bb
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2019/04/msg00017.html
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2022/03/msg00038.html

Scores

CVSS v3 5.4
EPSS 0.0131
EPSS Percentile 67.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (3)
cacti/cacti < 1.2.3
debian/debian_linux 8.0
debian/debian_linux 9.0
Published Apr 08, 2019
Tracked Since Feb 18, 2026