CVE-2017-11691 log
| Source |
|
| Severity | Medium |
| Remote | Yes |
| Type | Cross-site scripting |
| Description | A cross-site scripting vulnerability has been found in Cacti <= 1.1.13, in the user profile management page (auth_profile.php), allowing inject arbitrary web script or HTML via specially crafted HTTP Referer headers. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-365 | cacti | 1.1.13-1 | 1.1.14-1 | Medium | Fixed |
| Date | Advisory | Group | Package | Severity | Type |
|---|---|---|---|---|---|
| 27 Jul 2017 | ASA-201707-30 | AVG-365 | cacti | Medium | cross-site scripting |
| References |
|---|
http://seclists.org/oss-sec/2017/q3/217 https://github.com/Cacti/cacti/issues/867 https://github.com/Cacti/cacti/commit/104090aeead4aa433bf1f18cd6d52dcfeb71236c |