CVE-2024-30268
Last modified
CVE-2024-30268 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Cacti provides an operational monitoring and fault management framework. A reflected cross-site scripting vulnerability on the 1.3.x DEV branch allows attackers to obtain cookies of administrator and other users and fake their login using obtained cookies. EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
Cacti provides an operational monitoring and fault management framework. A reflected cross-site scripting vulnerability on the 1.3.x DEV branch allows attackers to obtain cookies of administrator and other users and fake their login using obtained cookies. This issue is fixed in commit a38b9046e9772612fda847b46308f9391a49891e.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-30268?
How severe is CVE-2024-30268?
How do I fix CVE-2024-30268?
Are you affected by CVE-2024-30268?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
