FlawAtlas
Search the atlas
OPENSUSE-SU-2021:1208-1 Not scored

Security update for cacti, cacti-spine

This update for cacti, cacti-spine fixes the following issues: cacti-spine 1.2.18: * Fix missing time parameter on FROM_UNIXTIME function cacti 1.2.18: * CVE-2020-14424: Lack of escaping on template import can lead to XSS exposure under 'midwinter' theme (boo#1188188) * Real time graphs can expose XSS issue This update was imported from the openSUSE:Leap:15.2:Update update project.

Exploit probability Not scored
Published August 28, 2021
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Package Hub 15 SP2 cacti
SUSE:Package Hub 15 SP2 cacti-spine

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities openSUSE-SU-2021:1208-1

This update for cacti, cacti-spine fixes the following issues: cacti-spine 1.2.18: * Fix missing time parameter on FROM_UNIXTIME function cacti 1.2.18: * CVE-2020-14424: Lack of escaping on template import can lead to XSS exposure under 'midwinter' theme (boo#1188188) * Real time graphs can expose XSS issue This update was imported from the openSUSE:Leap:15.2:Update update project.

View original source

05 / REFERENCES

Further evidence