Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the (1) drp_action parameter to cdef.php, (2) data_input.php, (3) data_queries.php, (4) data_sources.php, (5) data_templates.php, (6) graph_templates.php, (7) graphs.php, (8) host.php, or (9) host_templates.php or the (10) graph_template_input_id or (11) graph_template_id parameter to graph_templates_inputs.php.
CVSS Details
- CVSS 3.1 Base Score: 6.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade cacti | Aug 30, 2017 | Apr 23, 2014 |
| Debian | — | Upgrade cacti | Jul 30, 2024 | Jul 3, 2014 |
| Freebsd | — | Upgrade cacti | Dec 10, 2025 | Jun 21, 2015 |
| Gentoo Linux | — | Upgrade net-analyzer/cacti. | Oct 30, 2017 | Jul 3, 2014 |
| Suse | — | Upgrade cactiUpgrade cacti-doc | Dec 18, 2015 | Jul 3, 2014 |
| Ubuntu | — | Upgrade cacti | Nov 19, 2024 | Jul 3, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub