Skip to content

XSS and SQL Injection vulnerabilities

Moderate
netniV published GHSA-rwgg-5vv3-4hxp Jun 19, 2023

Package

No package listed

Affected versions

< 1.2.13

Patched versions

1.2.13

Description

NOTE: This is an example draft advisory and should not be published, please comment on whether you think we should include anything else with the advisory's on future disclosures

Impact

Multiple XSS issues existed within Cacti 1.2.x versions prior to 1.2.13.

Patches

This has now been patch with the release of 1.2.13

Workarounds

No end user workarounds are advised about from upgrading at this time.

References

See the following issue trackers:

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

CVE-2020-14295

Weaknesses

No CWEs