CVE-2014-5025

EPSS 0.45%

cacti - security update

Published: 10/20/2014Modified: 5/27/2026

Description

Cross-site scripting (XSS) vulnerability in data_sources.php in Cacti 0.8.8b allows remote authenticated users with console access to inject arbitrary web script or HTML via the name_cache parameter in a ds_edit action.

Affected packages (3)

References (1)