Bug ID 1224233
Summary VUL-0: CVE-2024-30268: cacti: reflected cross-site scripting vulnerability in display_settings
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.6
Hardware Other
URL https://smash.suse.de/issue/405121/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee Andreas.Stieger@gmx.de
Reporter smash_bz@suse.de
QA Contact security-team@suse.de
CC camila.matos@suse.com
Target Milestone ---
Found By Security Response Team
Blocker ---

Cacti provides an operational monitoring and fault management framework. A
reflected cross-site scripting vulnerability on the 1.3.x DEV branch allows
attackers to obtain cookies of administrator and other users and fake their
login using obtained cookies. This issue is fixed in commit
a38b9046e9772612fda847b46308f9391a49891e.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-30268
https://www.cve.org/CVERecord?id=CVE-2024-30268
https://github.com/Cacti/cacti/blob/08497b8bcc6a6037f7b1aae303ad8f7dfaf7364e/settings.php#L66
https://github.com/Cacti/cacti/commit/a38b9046e9772612fda847b46308f9391a49891e
https://github.com/Cacti/cacti/security/advisories/GHSA-9m3v-whmr-pc2q


You are receiving this mail because: