CVE-2014-2326: XSS
Cross-site scripting (XSS) vulnerability in cdef.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/cactito a version that resolves this vulnerability.Fixed in 1.2.16+ds1-2+deb11u3Fixed in 1.2.16+ds1-2+deb11u5Fixed in 1.2.24+ds1-1+deb12u5Fixed in 1.2.30+ds1-1
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2326?
CVE-2014-2326 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2014-2326?
To fix CVE-2014-2326, upgrade to the latest version of Cacti that is not affected, such as version 0.8.8c or later.
What versions of Cacti are vulnerable to CVE-2014-2326?
Cacti versions 0.8.7g, 0.8.8b, and earlier are vulnerable to CVE-2014-2326.
Can CVE-2014-2326 be exploited remotely?
Yes, CVE-2014-2326 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.
What are the potential impacts of CVE-2014-2326 if exploited?
Exploitation of CVE-2014-2326 can lead to unauthorized access, data theft, and other security risks associated with XSS attacks.