Bug 1194867 (CVE-2021-23225) - VUL-0: CVE-2021-23225: cacti: arbitrary web script or HTML injection in "new_username"
Summary: VUL-0: CVE-2021-23225: cacti: arbitrary web script or HTML injection in "new_...
Status: RESOLVED FIXED
Alias: CVE-2021-23225
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.3
Hardware: Other Other
: P5 - None : Normal (vote)
Target Milestone: ---
Assignee: Andreas Stieger
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/321022/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-01-19 09:15 UTC by Thomas Leroy
Modified: 2022-01-19 09:16 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Leroy 2022-01-19 09:15:28 UTC
rh#2042289

Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "new_username" field during creation of a new user via "Copy" method at user_admin.php.

Upstream commit:
https://github.com/Cacti/cacti/commit/2b8097c06030ab72c5b3bdadb23dceb5332f0e94

References:
https://github.com/Cacti/cacti/issues/1882
https://www.cacti.net/info/changelog
https://bugzilla.redhat.com/show_bug.cgi?id=2042289
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-23225
Comment 1 Thomas Leroy 2022-01-19 09:16:47 UTC
Fixing commit is the same as bnc#1194860, therefore this is also already fixed.