CVE-2018-10061: XSS
Published Apr 12, 2018
·Updated
Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENTQUOTES flag (these calls occur when the htmlescape function in lib/html.php is not used).
Affected Software
2 affected components
Cacti Cacti<=1.1.36
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
Apr 12, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2018-10061.
2
What is the severity level of CVE-2018-10061?
CVE-2018-10061 has a severity level of medium.
3
What is the Common Vulnerabilities and Exposures (CVE) score for CVE-2018-10061?
The Common Vulnerabilities and Exposures (CVE) score for CVE-2018-10061 is 5.4.
4
How does CVE-2018-10061 affect Cacti?
CVE-2018-10061 affects Cacti versions up to and including 1.1.36.
5
How can I fix the XSS vulnerability in Cacti?
To fix the XSS vulnerability in Cacti, you should update to version 1.1.37 or later.