CVE-2023-50250
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2023-50250 is a reflection cross-site scripting (XSS) vulnerability affecting version 1.2.25 of the open-source monitoring framework, Cacti. The issue occurs in `templates_import.php` when the server fails to validate XML template file names during import. In such cases, the server displays a JavaScript pop-up containing the unfiltered file name, allowing an attacker to inject malicious code and perform actions on behalf of other users. This could potentially result in unauthorized changes to system settings. At the time of publication, no patched versions have been released.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cacti
Affected Vendors
- Cacti