First published: Thu Nov 12 2020(Updated: )
A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti 1.2.13) due to Improper escaping of error message during template import preview in the xml_path field
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cacti Cacti | =1.2.13 | |
Debian Debian Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25706 is a cross-site scripting (XSS) vulnerability in templates_import.php in Cacti 1.2.13.
CVE-2020-25706 affects Cacti version 1.2.13.
The severity of CVE-2020-25706 is medium with a CVSS score of 6.1.
To fix CVE-2020-25706, you should update Cacti to version 1.2.14 or later.
You can find more information about CVE-2020-25706 on Red Hat's Bugzilla and GitHub Cacti repository.