Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-49086
HistoryDec 22, 2023 - 12:15 a.m.

Design/Logic Flaw

2023-12-2200:15:00
PRIOn knowledge base
www.prio-n.com
7
cacti
vulnerability
graphs_new.php
dom xss
attack
patch
version 1.2.26

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

23.0%

Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). Bypassing an earlier fix (CVE-2023-39360) that leads to a DOM XSS attack.
Exploitation of the vulnerability is possible for an authorized user. The vulnerable component is
the graphs_new.php. Impact of the vulnerability - execution of arbitrary javascript code in
the attacked user’s browser. This issue has been patched in version 1.2.26.

CPENameOperatorVersion
cactieq1.2.25

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

23.0%