VulnerabilityModified
CVE-2019-11025
In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options) in the View poller cache, leading to XSS.
MEDIUM 5.4EPSS 1.31%
Does this matter?
Lower severity and a low EPSS score (1.31%). Track it; it rarely justifies an emergency change on its own.
Description
In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options) in the View poller cache, leading to XSS.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.31% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- cacti/cacti · debian/debian linux
- Source
- cve@mitre.org
References
- https://github.com/Cacti/cacti/compare/6ea486a...99995bbRelease Notes, Third Party Advisory
- https://github.com/Cacti/cacti/issues/2581Exploit, Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/04/msg00017.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00038.htmlMailing List, Third Party Advisory
- https://github.com/Cacti/cacti/compare/6ea486a...99995bbRelease Notes, Third Party Advisory
- https://github.com/Cacti/cacti/issues/2581Exploit, Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/04/msg00017.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00038.htmlMailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.