Search CVE reports


Toggle filters

51 – 60 of 149 results


CVE-2023-30534

Medium priority
Needs evaluation

Cacti is an open source operational monitoring and fault management framework. There are two instances of insecure deserialization in Cacti version 1.2.24. While a viable gadget chain exists in Cacti’s vendor directory...

1 affected package

cacti

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cacti Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-48547

Medium priority
Needs evaluation

A reflected cross-site scripting (XSS) vulnerability in Cacti 0.8.7g and earlier allows unauthenticated remote attackers to inject arbitrary web script or HTML in the "ref" parameter at auth_changepassword.php.

1 affected package

cacti

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cacti Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-48538

Medium priority
Needs evaluation

In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() allows a zero as the password.

1 affected package

cacti

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cacti Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-46169

High priority

Some fixes available 3 of 6

Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to...

1 affected package

cacti

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cacti Not affected Fixed Fixed Fixed
Show less packages

CVE-2022-41444

Medium priority
Needs evaluation

Cross Site Scripting (XSS) vulnerability in Cacti 1.2.21 via crafted POST request to graphs_new.php.

1 affected package

cacti

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cacti Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-0730

Medium priority
Needs evaluation

Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.

1 affected package

cacti

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cacti Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-3816

Medium priority
Needs evaluation

Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary HTML in the group_prefix field during the creation of a new group via "Copy" method at user_group_admin.php.

1 affected package

cacti

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cacti Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-26247

Medium priority
Needs evaluation

As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" to successfully execute the JavaScript payload present in the "ref" URL parameter.

1 affected package

cacti

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cacti Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-23225

Medium priority
Needs evaluation

Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "new_username" field during creation of a new user via "Copy" method at user_admin.php.

1 affected package

cacti

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cacti Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-8813

Medium priority
Vulnerable

graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege.

1 affected package

cacti

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cacti Not affected Not affected Not affected Vulnerable
Show less packages