First published: Fri Aug 18 2017(Updated: )
A cross-site scripting vulnerability exists in Cacti 1.1.17 in the method parameter in spikekill.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cacti | =1.1.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-12927 is classified as medium due to its potential for cross-site scripting attacks.
To fix CVE-2017-12927, upgrade Cacti to version 1.1.28 or later where the vulnerability has been addressed.
CVE-2017-12927 can allow attackers to execute arbitrary JavaScript code in users' browsers, potentially stealing sensitive information.
CVE-2017-12927 specifically affects Cacti version 1.1.17 only.
CVE-2017-12927 is categorized as a cross-site scripting (XSS) vulnerability.