CVE-2017-11691 - log back

CVE-2017-11691 created at 25 Sep 2019 19:31:40
Severity
+ Medium
Remote
+ Remote
Type
+ Cross-site scripting
Description
+ A cross-site scripting vulnerability has been found in Cacti <= 1.1.13, in the user profile management page (auth_profile.php), allowing inject arbitrary web script or HTML via specially crafted HTTP Referer headers.
References
+ http://seclists.org/oss-sec/2017/q3/217
+ https://github.com/Cacti/cacti/issues/867
+ https://github.com/Cacti/cacti/commit/104090aeead4aa433bf1f18cd6d52dcfeb71236c
Notes