CVE-2020-7106: XSS
Cacti 1.2.8 has stored XSS in datasources.php, colortemplatesitem.php, graphs.php, graphitems.php, lib/apiautomation.php, useradmin.php, and usergroupadmin.php, as demonstrated by the description parameter in datasources.php (a raw string from the database that is displayed by $header to trigger the XSS).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-7106?
CVE-2020-7106 is a stored Cross-Site Scripting (XSS) vulnerability in Cacti 1.2.8.
Which files are affected by CVE-2020-7106?
CVE-2020-7106 affects the following files: data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php.
What is the severity of CVE-2020-7106?
CVE-2020-7106 has a severity rating of 6.1, which is considered medium.
How can I fix CVE-2020-7106?
To fix CVE-2020-7106, you should update Cacti to version 1.2.9 or apply the necessary patches provided by the vendor.
Where can I find more information about CVE-2020-7106?
You can find more information about CVE-2020-7106 at the following references: [Reference 1](http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00001.html), [Reference 2](http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00005.html), [Reference 3](http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00042.html).