CVE-2020-7106
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS).
- Cacti
- < 1.2.9
- Fix
- Available
- CVSS 3.1
- 6.1 MEDIUM
- EPSS
- 2.1% (80th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2020-01-16
CVE-2020-7106 at NVD
No indexed exploits for CVE-2020-7106 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2020-7106 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.