FlawAtlas
Search the atlas
OPENSUSE-SU-2021:1190-1 Not scored

Security update for cacti, cacti-spine

This update for cacti, cacti-spine fixes the following issues: cacti-spine 1.2.18: * Fix missing time parameter on FROM_UNIXTIME function cacti 1.2.18: * CVE-2020-14424: Lack of escaping on template import can lead to XSS exposure under 'midwinter' theme (boo#1188188) * Real time graphs can expose XSS issue

Exploit probability Not scored
Published August 25, 2021
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Package Hub 12 cacti
SUSE:Package Hub 12 cacti-spine
SUSE:Package Hub 15 SP3 cacti
SUSE:Package Hub 15 SP3 cacti-spine
openSUSE:Leap 15.2 cacti
openSUSE:Leap 15.2 cacti-spine
openSUSE:Leap 15.3 cacti
openSUSE:Leap 15.3 cacti-spine

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities openSUSE-SU-2021:1190-1

This update for cacti, cacti-spine fixes the following issues: cacti-spine 1.2.18: * Fix missing time parameter on FROM_UNIXTIME function cacti 1.2.18: * CVE-2020-14424: Lack of escaping on template import can lead to XSS exposure under 'midwinter' theme (boo#1188188) * Real time graphs can expose XSS issue

View original source

05 / REFERENCES

Further evidence