[Pkg-cacti-maint] Bug#949996: cacti: CVE-2020-7106

Salvatore Bonaccorso carnil at debian.org
Tue Jan 28 07:39:37 GMT 2020


Source: cacti
Version: 1.2.8+ds1-1
Severity: important
Tags: security upstream
Forwarded: https://github.com/Cacti/cacti/issues/3191

Hi,

The following vulnerability was published for cacti.

CVE-2020-7106[0]:
| Cacti 1.2.8 has stored XSS in data_sources.php,
| color_templates_item.php, graphs.php, graph_items.php,
| lib/api_automation.php, user_admin.php, and user_group_admin.php, as
| demonstrated by the description parameter in data_sources.php (a raw
| string from the database that is displayed by $header to trigger the
| XSS).


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2020-7106
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7106
[1] https://github.com/Cacti/cacti/issues/3191

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



More information about the Pkg-cacti-maint mailing list