We found results for “”
CVE-2023-49088
Date: December 22, 2023
Cacti is an open source operational monitoring and fault management framework. The fix applied for CVE-2023-39515 in version 1.2.25 is incomplete as it enables an adversary to have a victim browser execute malicious code when a victim user hovers their mouse over the malicious data source path in "data_debug.php". To perform the cross-site scripting attack, the adversary needs to be an authorized cacti user with the following permissions: "General Administration>Sites/Devices/Data". The victim of this attack could be any account with permissions to view "http://<HOST>/cacti/data_debug.php". As of time of publication, no complete fix has been included in Cacti.
Language: PHP
Severity Score
Related Resources (8)
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | HIGH |
| User Interaction (UI): | REQUIRED |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


