Medium severity5.4NVD Advisory· Published Aug 21, 2017· Updated May 13, 2026
CVE-2017-12978
CVE-2017-12978
Description
lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/Cacti/cacti/blob/develop/docs/CHANGELOGnvdIssue TrackingPatchThird Party Advisory
- github.com/Cacti/cacti/commit/9c610a7a4e29595dcaf7d7082134e4b89619ea24nvdIssue TrackingPatchThird Party Advisory
- github.com/Cacti/cacti/issues/918nvdIssue TrackingPatchThird Party Advisory
- www.securitytracker.com/id/1039226nvd
News mentions
0No linked articles in our index yet.