Total vulnerabilities in the database
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS).
Software | From | Fixed in |
---|---|---|
cacti / cacti | - | 1.2.9 |
debian / debian_linux | 8.0 | 8.0.x |
debian / debian_linux | 9.0 | 9.0.x |
opensuse / leap | 15.1 | 15.1.x |
opensuse / backports_sle | 15.0-sp1 | 15.0-sp1.x |
fedoraproject / fedora | 30 | 30.x |
fedoraproject / fedora | 31 | 31.x |
fedoraproject / extra_packages_for_enterprise_linux | 8.0 | 8.0.x |
fedoraproject / extra_packages_for_enterprise_linux | 9.0 | 9.0.x |
fedoraproject / extra_packages_for_enterprise_linux | 7.0 | 7.0.x |