CVE-2024-43364
CVSS 3.1 Score 8.2 of 10 (high)
Details
Summary
CVE-2024-43364 is a stored XSS vulnerability affecting Cacti, an open-source performance and fault management framework. Malicious users with the privilege to create external links can manipulate the `title` parameter during the creation process, leading to unvalidated user input being stored in the database and reflected back to users in index.php. This results in a stored XSS vulnerability, allowing attackers to inject and execute malicious scripts on unsuspecting users. The vulnerability, which can lead to various attacks including session hijacking and data theft, has been addressed in Cacti version 1.2.28. It is recommended that all users upgrade as soon as possible, as there are currently no known workarounds for this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cacti
- Cacti Cacti
Affected Vendors
- Cacti