CVE-2019-11025 Information

Description

In clearFilter() in utilities.php in Cacti before 1.2.3 no escaping occurs before printing out the value of the SNMP community string (SNMP Options) in the View poller cache leading to XSS.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Reference

https://github.com/Cacti/cacti/compare/6ea486a…99995bb https://github.com/Cacti/cacti/issues/2581 https://lists.debian.org/debian-lts-announce/2019/04/msg00017.html

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

5.4

Share on: