HTTP: Cacti Group Cacti Automation Graph and Tree Rules name Stored Cross-Site Scripting
This signature detects attempts to exploit a known cross-site scripting vulnerability against Cacti. It is due to insufficient validation of user-supplied input. Attackers can steal cookie-based authentication credentials and launch other attacks.
Extended Description
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules_form_save()` function in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the HTML statement in `form_confirm()` function from `lib/html.php` , finally resulting in cross-site scripting. Version 1.2.27 contains a patch for the issue.
Affected Products
Fedoraproject fedora
References
CVE: CVE-2024-43364
URL: https://github.com/Cacti/cacti/security/advisories/GHSA-p4ch-7hjw-6m87 https://github.com/Cacti/cacti/security/advisories/GHSA-wh9c-v56x-v77c https://github.com/Cacti/cacti/security/advisories/GHSA-49f2-hwx9-qffr https://github.com/Cacti/cacti/security/advisories/GHSA-fgc6-g8gc-wcg5
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Cacti
Fedoraproject