Bug 1999783 (CVE-2020-23226) - CVE-2020-23226 cacti: multiple XSS vulnerabilities
Summary: CVE-2020-23226 cacti: multiple XSS vulnerabilities
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2020-23226
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2021-08-31 18:02 UTC by Guilherme de Almeida Suckevicz
Modified: 2021-10-28 05:30 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-10-28 05:30:42 UTC
Embargoed:


Attachments (Terms of Use)

Description Guilherme de Almeida Suckevicz 2021-08-31 18:02:33 UTC
Multiple Cross Site Scripting (XSS) vulneratiblities exist in Cacti 1.2.12 in (1) reports_admin.php, (2) data_queries.php, (3) datat.ph_inpup, (4) graph_templates.php, (5) graphs.php, (6) reports_admin.php, and (7) data_input.php.

References:
https://github.com/Cacti/cacti/issues/3549


Note You need to log in before you can comment on or make changes to this bug.