Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-27082
HistoryMay 14, 2024 - 12:00 a.m.

CVE-2024-27082

2024-05-1400:00:00
ubuntu.com
ubuntu.com
6
cacti
monitoring tool
stored cross-site scripting
version 1.2.27
fault management
target server

CVSS3

7.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H

AI Score

6.2

Confidence

High

EPSS

0

Percentile

9.0%

Cacti provides an operational monitoring and fault management framework.
Versions of Cacti prior to 1.2.27 are vulnerable to stored cross-site
scripting, a type of cross-site scripting where malicious scripts are
permanently stored on a target server and served to users who access a
particular page. Version 1.2.27 contains a patch for the issue.

CVSS3

7.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H

AI Score

6.2

Confidence

High

EPSS

0

Percentile

9.0%