PT-2026-52135 · Cacti · Cacti
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Cacti versions prior to 1.2.31
Description
Reflected Cross-Site Scripting (XSS) occurs in the JavaScript context of the 'auth profile.php' endpoint through the
tab parameter. Reflected XSS is a type of attack where a malicious script is reflected off a web application to the victim's browser.Recommendations
Update to version 1.2.31.
As a temporary workaround, restrict access to the 'auth profile.php' endpoint or avoid using the
tab parameter until the update is applied.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cacti