Total vulnerabilities in the database
Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "new_username" field during creation of a new user via "Copy" method at user_admin.php.
Software | From | Fixed in |
---|---|---|
cacti / cacti | 1.1.38 | 1.1.38.x |
debian / debian_linux | 9.0 | 9.0.x |