Skip to content

Further fixes for grave character security protection #4356

@ddb4github

Description

@ddb4github

Describe the bug

  • cacti/data_templates.php:
    Name column does not escape grave(`) char.
    Example:
    Cacti Stats - Export Duration	onmouseover=`alert(188)`
    
    Ref: https://davidmurdoch.com/2017/09/02/the-grave-accent-and-xss/
  • graph_templates.php?action=template_edit&id=123
    Graph Item Inputs-->Name column, cruly braces(})
    Example:
    a onmouseover=55+{toString:alert}//
    

To Reproduce

Hardly reproduce under Firefox/Chrome

Metadata

Metadata

Assignees

No one assigned

    Labels

    SECURITYA security issue reported through CVEduplicateDuplicate of another issueresolvedA fixed issue

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions