First published: Thu Apr 12 2018(Updated: )
Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to use of the sanitize_uri function in lib/functions.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cacti Cacti | <=1.1.36 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10060 is a vulnerability in Cacti before version 1.1.37 that allows for cross-site scripting (XSS) attacks due to improper rejection of unintended characters.
The severity of CVE-2018-10060 is rated as medium with a CVSS score of 5.4.
CVE-2018-10060 affects Cacti before version 1.1.37 by allowing attackers to perform XSS attacks due to the improper rejection of unintended characters.
Cacti versions up to and including 1.1.36 are affected by CVE-2018-10060, as well as Debian Linux version 9.0.
To fix CVE-2018-10060, it is recommended to upgrade to Cacti version 1.1.37 or newer and apply the necessary patches if available.