VulnerabilityModified
CVE-2018-20726
A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname field for Devices.
MEDIUM 5.4EPSS 1.05%
Does this matter?
Lower severity and a low EPSS score (1.05%). Track it; it rarely justifies an emergency change on its own.
Description
A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname field for Devices.
- CVSS 3.0
- 5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.05% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- cacti/cacti
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00042.html
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00048.html
- https://github.com/Cacti/cacti/blob/develop/CHANGELOGRelease Notes, Third Party Advisory
- https://github.com/Cacti/cacti/commit/80c2a88fb2afb93f87703ba4641f9970478c102dPatch, Third Party Advisory
- https://github.com/Cacti/cacti/issues/2213Exploit, Issue Tracking, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00042.html
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00048.html
- https://github.com/Cacti/cacti/blob/develop/CHANGELOGRelease Notes, Third Party Advisory
- https://github.com/Cacti/cacti/commit/80c2a88fb2afb93f87703ba4641f9970478c102dPatch, Third Party Advisory
- https://github.com/Cacti/cacti/issues/2213Exploit, Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.