acti is an open source performance and fault management framework. The `fileurl` parameter is not properly sanitized when saving external links in `links.php` . Morever, the said fileurl is placed in some html code which is passed to the `print` function in `link.php` and `index.php`, finally leading to stored XSS. Users with the privilege to create external links can manipulate the `fileurl` parameter in the http post request while creating external links to perform stored XSS attacks. The vulnerability known as XSS (Cross-Site Scripting) occurs when an application allows untrusted user input to be displayed on a web page without proper validation or escaping. This issue has been addressed in release version 1.2.28. All users are advised to upgrade. There are no known workarounds for this issue.
| Link | Resource |
|---|---|
| https://github.com/Cacti/cacti/security/advisories/GHSA-wh9c-v56x-v77c | Exploit Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2025/02/msg00010.html |
03 Nov 2025, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.3 |
17 Oct 2024, 18:14
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/Cacti/cacti/security/advisories/GHSA-wh9c-v56x-v77c - Exploit, Third Party Advisory | |
| First Time |
Cacti cacti
Cacti |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
| CPE | cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:* |
10 Oct 2024, 12:57
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
07 Oct 2024, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2024-10-07 21:15
Updated : 2025-11-03 21:16
NVD link : CVE-2024-43362
Mitre link : CVE-2024-43362
CVE.ORG link : CVE-2024-43362
JSON object : View
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')