Bugzilla – Bug 1194867
VUL-0: CVE-2021-23225: cacti: arbitrary web script or HTML injection in "new_username"
Last modified: 2022-01-19 09:16:47 UTC
rh#2042289 Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "new_username" field during creation of a new user via "Copy" method at user_admin.php. Upstream commit: https://github.com/Cacti/cacti/commit/2b8097c06030ab72c5b3bdadb23dceb5332f0e94 References: https://github.com/Cacti/cacti/issues/1882 https://www.cacti.net/info/changelog https://bugzilla.redhat.com/show_bug.cgi?id=2042289 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-23225
Fixing commit is the same as bnc#1194860, therefore this is also already fixed.