CVE-2019-11025
MEDIUMCacti < 1.2.3 - Stored Cross-Site Scripting via SNMP Community String
Title source: llmDescription
In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options) in the View poller cache, leading to XSS.
References (4)
Core 4
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/Cacti/cacti/issues/2581
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/Cacti/cacti/compare/6ea486a...99995bb
Mailing List, Third Party Advisory mailing-list
x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2019/04/msg00017.html
Mailing List, Third Party Advisory mailing-list
x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2022/03/msg00038.html
Scores
CVSS v3
5.4
EPSS
0.0131
EPSS Percentile
67.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (3)
cacti/cacti
< 1.2.3
debian/debian_linux
8.0
debian/debian_linux
9.0
Published
Apr 08, 2019
Tracked Since
Feb 18, 2026