CVE-2022-48547
- EPSS 0.6%
- Veröffentlicht 22.08.2023 19:16:31
- Zuletzt bearbeitet 21.11.2024 07:33:30
A reflected cross-site scripting (XSS) vulnerability in Cacti 0.8.7g and earlier allows unauthenticated remote attackers to inject arbitrary web script or HTML in the "ref" parameter at auth_changepassword.php.
CVE-2022-41444
- EPSS 0.29%
- Veröffentlicht 22.08.2023 19:16:28
- Zuletzt bearbeitet 04.11.2025 16:15:52
Cross Site Scripting (XSS) vulnerability in Cacti 1.2.21 via crafted POST request to graphs_new.php.
CVE-2023-37543
- EPSS 0.47%
- Veröffentlicht 10.08.2023 15:15:09
- Zuletzt bearbeitet 21.11.2024 08:11:54
Cacti before 1.2.6 allows IDOR (Insecure Direct Object Reference) for accessing any graph via a modified local_graph_id parameter to graph_xport.php. This is a different vulnerability than CVE-2019-16723.
CVE-2022-46169
- EPSS 94.47%
- Veröffentlicht 05.12.2022 21:15:10
- Zuletzt bearbeitet 24.10.2025 14:47:01
Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbitrary code o...
CVE-2022-0730
- EPSS 0.31%
- Veröffentlicht 03.03.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:39:16
Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.
CVE-2021-23225
- EPSS 0.81%
- Veröffentlicht 19.01.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:24
Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "new_username" field during creation of a new user via "Copy" method at user_admin.php.
CVE-2021-26247
- EPSS 43.78%
- Veröffentlicht 19.01.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:58
As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" to successfully execute the JavaScript payload present in the "ref" URL parameter.
CVE-2021-3816
- EPSS 0.44%
- Veröffentlicht 19.01.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:31
Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary HTML in the group_prefix field during the creation of a new group via "Copy" method at user_group_admin.php.
CVE-2020-14424
- EPSS 0.39%
- Veröffentlicht 14.11.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:03:14
Cacti before 1.2.18 allows remote attackers to trigger XSS via template import for the midwinter theme.
CVE-2020-23226
- EPSS 1.29%
- Veröffentlicht 27.08.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 05:13:39
Multiple Cross Site Scripting (XSS) vulneratiblities exist in Cacti 1.2.12 in (1) reports_admin.php, (2) data_queries.php, (3) data_input.php, (4) graph_templates.php, (5) graphs.php, (6) reports_admin.php, and (7) data_input.php.