Medium severity5.4NVD Advisory· Published Aug 21, 2017· Updated Jun 17, 2026
CVE-2017-12978
CVE-2017-12978
Description
lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*range: <=1.1.17
- (no CPE)range: <1.1.18
Patches
Vulnerability mechanics
References
4- github.com/Cacti/cacti/blob/develop/docs/CHANGELOGnvdIssue TrackingPatchThird Party Advisory
- github.com/Cacti/cacti/commit/9c610a7a4e29595dcaf7d7082134e4b89619ea24nvdIssue TrackingPatchThird Party Advisory
- github.com/Cacti/cacti/issues/918nvdIssue TrackingPatchThird Party Advisory
- www.securitytracker.com/id/1039226nvd
News mentions
0No linked articles in our index yet.