Cacti before 1.2.18 allows remote attackers to trigger XSS via template import for the midwinter theme.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14424
Reference (s):
- https://bugzilla.redhat.com/show_bug.cgi?id=2001016
- https://github.com/Cacti/cacti/pull/4261

