CVE-2024-31444 Information
May 15, 2024
cve
Description
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27 some of the data stored in automation_tree_rules_form_save() function in automation_tree_rules.php is not thoroughly checked and is used to concatenate the HTML statement in form_confirm() function from lib/html.php finally resulting in cross-site scripting. Version 1.2.27 contains a patch for the issue.
Reference
https://github.com/Cacti/cacti/security/advisories/GHSA-p4ch-7hjw-6m87
Share on: