CVE-2024-43364

CVSS 3.1 Score 8.2 of 10 (high)

Details

Published Oct 7, 2024
Updated: Oct 17, 2024
CWE ID 79

Summary

CVE-2024-43364 is a stored XSS vulnerability affecting Cacti, an open-source performance and fault management framework. Malicious users with the privilege to create external links can manipulate the `title` parameter during the creation process, leading to unvalidated user input being stored in the database and reflected back to users in index.php. This results in a stored XSS vulnerability, allowing attackers to inject and execute malicious scripts on unsuspecting users. The vulnerability, which can lead to various attacks including session hijacking and data theft, has been addressed in Cacti version 1.2.28. It is recommended that all users upgrade as soon as possible, as there are currently no known workarounds for this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share