Bugzilla – Bug 1178677
VUL-1: CVE-2020-25706: cacti: Improper escaping of error message leads to XSS during template import preview
Last modified: 2020-11-11 17:57:09 UTC
rh#1896695 A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti 1.2.13) due to Improper escaping of error message during template import preview in the xml_path field References: https://bugzilla.redhat.com/show_bug.cgi?id=1896695 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-25706
Already fixed via bug 1174850. https://lists.opensuse.org/opensuse-updates/2020-08/msg00059.html *** This bug has been marked as a duplicate of bug 1174850 ***