CVE-2017-11691: XSS
Published Jul 27, 2017
·Updated
Cross-site scripting (XSS) vulnerability in authprofile.php in Cacti 1.1.13 allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.
Affected Software
1 affected component
Cacti Cacti=1.1.13
Remediation
Event History
Jul 27, 2017
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11691?
The severity of CVE-2017-11691 is rated as medium with a score of 5.4.
2
How do I fix CVE-2017-11691?
To fix CVE-2017-11691, update Cacti to version 1.1.14 or later where the vulnerability is addressed.
3
What type of vulnerability is CVE-2017-11691?
CVE-2017-11691 is a Cross-site scripting (XSS) vulnerability affecting Cacti version 1.1.13.
4
What can attackers do with CVE-2017-11691?
Attackers can exploit CVE-2017-11691 to inject arbitrary web scripts or HTML through specially crafted HTTP Referer headers.
5
Which version of Cacti is affected by CVE-2017-11691?
Cacti version 1.1.13 is affected by CVE-2017-11691.