Sploitus

CVE-2023-39360

No indexed exploits for CVE-2023-39360 yet

Cacti is an open source operational monitoring and fault management framework.Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data. The vulnerability is found in `graphs_new.php`. Several validations are performed, but the `returnto` parameter is directly passed to `form_save_button`. In order to bypass this validation, returnto must contain `host.php`. This vulnerability has been addressed in version 1.2.25. Users are advised to upgrade. Users unable to update should manually filter HTML output.

Affected products
Alt Linux, Cacti
Cacti
= 1.2.24
Fix
Available
CVSS 3.1
6.1 MEDIUM
EPSS
0.8% (52th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2023-09-05
CVE-2023-39360 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2023-39360 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2023-39360 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.