CVEs Blog | G5 Cyber Security

CVE-2020-25706 – A cross-site scripting (XSS) vulnerability exists in templates_import.php

A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti 1.2.13) due to Improper escaping of error message during template import preview in the xml_path field

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25706

Reference (s):

Exit mobile version