CVE-2019-11025
MEDIUM5.4EPSS 0.64%cacti - security update
Published: 4/8/2019Modified: 5/27/2026
Description
In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options) in the View poller cache, leading to XSS.
Affected packages (2)
- Debian/cactifrom 0, < 1.2.2+ds1-2
- Debian/cactifrom 0, < 0.8.8b+dfsg-8+deb8u7
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |