Medium severity4.8OSV Advisory· Published Jan 16, 2019· Updated Jun 17, 2026
CVE-2018-20725
CVE-2018-20725
Description
A cross-site scripting (XSS) vulnerability exists in graph_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Graph Vertical Label.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- osv-coords7 versionspkg:rpm/opensuse/cacti&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/cacti&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/cacti-spine&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/cacti&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/suse/cacti-spine&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/suse/cacti&distro=SUSE%20Package%20Hub%2012pkg:rpm/suse/cacti-spine&distro=SUSE%20Package%20Hub%2012
< 1.2.18-1.2+ 6 more
- (no CPE)range: < 1.2.18-1.2
- (no CPE)range: < 1.2.9-lp151.3.3.1
- (no CPE)range: < 1.2.9-lp151.3.3.1
- (no CPE)range: < 1.2.9-bp151.4.3.1
- (no CPE)range: < 1.2.9-bp151.4.3.1
- (no CPE)range: < 1.2.11-5.1
- (no CPE)range: < 1.2.11-2.1
<1.2.0+ 2 more
- (no CPE)range: <1.2.0
- (no CPE)range: release/1.0.0, release/1.0.1, release/1.0.2, …
- cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*range: <1.2.0
Patches
Vulnerability mechanics
References
7- github.com/Cacti/cacti/commit/80c2a88fb2afb93f87703ba4641f9970478c102dnvdPatchThird Party Advisory
- github.com/Cacti/cacti/issues/2214nvdExploitIssue TrackingThird Party Advisory
- github.com/Cacti/cacti/blob/develop/CHANGELOGnvdRelease NotesThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-03/msg00001.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2020-03/msg00005.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2020-04/msg00042.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2020-04/msg00048.htmlnvd
News mentions
0No linked articles in our index yet.