CVE-2019-11025

medium

Description

In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options) in the View poller cache, leading to XSS.

References

https://lists.debian.org/debian-lts-announce/2022/03/msg00038.html

https://lists.debian.org/debian-lts-announce/2019/04/msg00017.html

https://github.com/Cacti/cacti/issues/2581

https://github.com/Cacti/cacti/compare/6ea486a...99995bb

Details

Source: Mitre, NVD

Published: 2019-04-08

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 3.5

Vector: CVSS2#AV:N/AC:M/Au:S/C:N/I:P/A:N

Severity: Low

CVSS v3

Base Score: 5.4

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Severity: Medium