Skip to content

Device, Graph, Graph Template, and Graph Items may be vulnerable to XSS issues #4576

@TheWitness

Description

@TheWitness

Describe the bug

If any of the above Cacti Graph objects have a title with an stored XSS script value, it can be executed during Cacti's Callback process. This can lead to XSS issues in Cacti.

To Reproduce

Steps to reproduce the behavior:

  1. Save an object above with a title of <script>alert('something');<?script>

  2. Goto any Cacti page that includes one of these object callbacks

  3. Search on something

  4. See error

Expected behavior

Less bugs in Cacti!

Metadata

Metadata

Assignees

No one assigned

    Labels

    SECURITYA security issue reported through CVEbugUndesired behaviour

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions