First published: Fri Jul 10 2015(Updated: )
Cross-site scripting (XSS) vulnerability in settings.php in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cacti | <=0.8.8c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2967 is classified as a medium-severity Cross-site Scripting (XSS) vulnerability.
To fix CVE-2015-2967, upgrade Cacti to version 0.8.8d or later.
CVE-2015-2967 affects Cacti versions prior to 0.8.8d, specifically up to and including 0.8.8c.
Yes, CVE-2015-2967 can lead to significant security risks by allowing remote attackers to inject arbitrary scripts or HTML.
Yes, the patch for CVE-2015-2967 is included in the release of Cacti version 0.8.8d.