CVE-2018-20726

NameCVE-2018-20726
DescriptionA cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname field for Devices.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitylow (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
cacti (PTS)jessie0.8.8b+dfsg-8+deb8u6vulnerable
jessie (security)0.8.8b+dfsg-8+deb8u4vulnerable
stretch0.8.8h+ds1-10vulnerable
buster1.2.1+ds1-1fixed
sid1.2.1+ds1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
cactisource(unstable)1.2.1+ds1-1low

Notes

[stretch] - cacti <no-dsa> (Minor issue)
[jessie] - cacti <ignored> (Minor issue)
https://github.com/Cacti/cacti/commit/80c2a88fb2afb93f87703ba4641f9970478c102d
https://github.com/Cacti/cacti/issues/2213

Search for package or bug name: Reporting problems