Bug 1178677 (CVE-2020-25706) - VUL-1: CVE-2020-25706: cacti: Improper escaping of error message leads to XSS during template import preview
Summary: VUL-1: CVE-2020-25706: cacti: Improper escaping of error message leads to XSS...
Status: RESOLVED DUPLICATE of bug 1174850
Alias: CVE-2020-25706
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.1
Hardware: Other Other
: P4 - Low : Normal (vote)
Target Milestone: ---
Assignee: Andreas Stieger
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/271338/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-11-11 14:56 UTC by Robert Frohl
Modified: 2020-11-11 17:57 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Frohl 2020-11-11 14:56:12 UTC
rh#1896695

A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti
1.2.13) due to Improper escaping of error message during template
import preview in the xml_path field

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1896695
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-25706
Comment 1 Andreas Stieger 2020-11-11 17:57:09 UTC
Already fixed via bug 1174850.
https://lists.opensuse.org/opensuse-updates/2020-08/msg00059.html

*** This bug has been marked as a duplicate of bug 1174850 ***