Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2020-14424: lack of escaping on template import can lead to XSS

Cacti before 1.2.18 allows remote attackers to trigger XSS via template import for the midwinter theme.

CVE
#xss#vulnerability#linux#red_hat#git

Bug 2001016 (CVE-2020-14424) - CVE-2020-14424 cacti: lack of escaping on template import can lead to XSS

Summary: CVE-2020-14424 cacti: lack of escaping on template import can lead to XSS

Keywords:

Status:

CLOSED UPSTREAM

Alias:

CVE-2020-14424

Product:

Security Response

Classification:

Other

Component:

vulnerability

Sub Component:

Version:

unspecified

Hardware:

All

OS:

Linux

Priority:

medium

Severity:

medium

Target Milestone:

Assignee:

Red Hat Product Security

QA Contact:

Docs Contact:

URL:

Whiteboard:

Depends On:

2001017 2001018

Blocks:

TreeView+

depends on / blocked

Reported:

2021-09-03 14:43 UTC by Marian Rehak

Modified:

2021-09-03 20:33 UTC (History)

CC List:

3 users (show)

Fixed In Version:

cacti 1.2.18

Doc Type:

If docs needed, set a value

Doc Text:

Clone Of:

Environment:

Last Closed:

2021-09-03 20:33:21 UTC

Attachments

(Terms of Use)

Add an attachment (proposed patch, testcase, etc.)

Description Marian Rehak 2021-09-03 14:43:18 UTC

Lack of escaping on template import can lead to XSS exposure under ‘midwinter’ theme.

Upstream Issue:

https://github.com/Cacti/cacti/pull/4261

Comment 1 Marian Rehak 2021-09-03 14:43:38 UTC

Created cacti tracking bugs for this issue:

Affects: epel-all [bug 2001018] Affects: fedora-all [bug 2001017]

Comment 2 Product Security DevOps Team 2021-09-03 20:33:21 UTC

This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.

Note You need to log in before you can comment on or make changes to this bug.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907