5.4
CVSSv3

CVE-2019-11025

Published: 08/04/2019 Updated: 24/05/2022
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

In clearFilter() in utilities.php in Cacti prior to 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options) in the View poller cache, leading to XSS.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cacti cacti

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #926700 cacti: CVE-2019-11025 - XSS in utilitiesphp Package: src:cacti; Maintainer for src:cacti is Cacti Maintainer <pkg-cacti-maint@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 9 Apr 2019 10:33:01 UTC Severity: important Tags: security, upstre ...