First published: Mon Jul 10 2017(Updated: )
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cacti | =1.1.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11163 has been classified as a moderate severity cross-site scripting (XSS) vulnerability.
To remediate CVE-2017-11163, upgrade to a patched version of Cacti that does not include this vulnerability.
CVE-2017-11163 affects users of Cacti version 1.1.12 who are authenticated and can manipulate HTTP Referer headers.
Exploitation of CVE-2017-11163 allows attackers to inject arbitrary web scripts or HTML, potentially compromising user sessions.
CVE-2017-11163 highlights a specific cross-site scripting issue, but users should review other advisories for comprehensive security.