Bugzilla – Bug 888686
VUL-0: CVE-2014-5025 CVE-2014-5026: cacti: cross-site scripting issues
Last modified: 2015-06-11 09:51:42 UTC
CVE-2014-5025 CVE-2014-5026 A number of cross-site scripting issues were found in Cacti. A user with console access could use these flaws to perform cross-site scripting attacks against other Cacti users. References: http://bugs.cacti.net/view.php?id=2456 (security advisory) http://bugs.cacti.net/file_download.php?file_id=1125&type=bug (patch suggestion) https://bugzilla.redhat.com/show_bug.cgi?id=1121466
bugbot adjusting priority
Factory has 0.8.8c which contains the fix. Can you please submit for 13.1 and 13.2?
Already fixed, openSUSE 13.1 and 13.2 are at 0.8.8c via version update.