Cacti.graphs.PHP.XSS

description-logoDescription

This indicates an attack attempt to exploit a Cross-Site Scripting vulnerability in Cacti, which was discovered by Fortinet's FortiGuard Labs.
The vulnerability exists due to insufficiently sanitizing user-supplied data in HTTP request sent to graphs.php so that remote attackers can exploit it to launch XSS attack.

affected-products-logoAffected Products

Cacti Version 0.8.8c

Impact logoImpact

System Compromise: Remote attackers can execute arbitrary script code within the context of the target user's browser.

recomended-action-logoRecommended Actions

Upgrade to the latest version, available from the website.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)