Vulnerability Description
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cacti | Cacti | < 1.2.9 |
| Debian | Debian Linux | 8.0 |
| Opensuse | Backports Sle | 15.0 |
| Opensuse | Leap | 15.1 |
| Suse | Package Hub | - |
| Suse | Linux Enterprise | 12.0 |
| Fedoraproject | Extra Packages For Enterprise Linux | 7.0 |
| Fedoraproject | Fedora | 30 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00001.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00005.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00042.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00048.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00032.htmlMailing ListThird Party Advisory
- https://github.com/Cacti/cacti/issues/3191ExploitThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/01/msg00014.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00038.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.gentoo.org/glsa/202003-40Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00001.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00005.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00042.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00048.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2020-7106?
CVE-2020-7106 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the descript...
How severe is CVE-2020-7106?
CVE-2020-7106 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-7106?
Check the references section above for vendor advisories and patch information. Affected products include: Cacti Cacti, Debian Debian Linux, Opensuse Backports Sle, Opensuse Leap, Suse Package Hub.