CVE-2023-49086

CVSS V2 None CVSS V3 None
Description
Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). A vulnerability in versions prior to 1.2.27 bypasses an earlier fix for CVE-2023-39360, therefore leading to a DOM XSS attack. Exploitation of the vulnerability is possible for an authorized user. The vulnerable component is the `graphs_new.php`. The impact of the vulnerability is execution of arbitrary JavaScript code in the attacked user's browser. This issue has been patched in version 1.2.27.
Overview
  • CVE ID
  • CVE-2023-49086
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-12-21T23:29:45.134Z
  • Last Modified Date
  • 2024-06-03T12:54:31.990Z
History
Created Old Value New Value Data Type Notes
2024-06-25 13:21:17 Added to TrackCVE