CVE-2024-27082: Cacti Cross-site Scripting vulnerability when managing trees
Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 are vulnerable to stored cross-site scripting, a type of cross-site scripting where malicious scripts are permanently stored on a target server and served to users who access a particular page. Version 1.2.27 contains a patch for the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27082?
CVE-2024-27082 has a high severity rating due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2024-27082?
To fix CVE-2024-27082, you should upgrade Cacti to version 1.2.27 or later.
What versions of Cacti are affected by CVE-2024-27082?
CVE-2024-27082 affects all versions of Cacti prior to 1.2.27.
Can CVE-2024-27082 lead to data breaches?
Yes, CVE-2024-27082 can facilitate data breaches by allowing attackers to execute malicious scripts on affected systems.
Is there a workaround for CVE-2024-27082?
There are no reliable workarounds for CVE-2024-27082; upgrading to the latest version is the recommended action.