Medium severity5.4NVD Advisory· Published Nov 12, 2020· Updated Jun 17, 2026
CVE-2020-25706
CVE-2020-25706
Description
A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti 1.2.13) due to Improper escaping of error message during template import preview in the xml_path field
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- The Cacti Group, Inc./cactiv5Range: 1.2.13
cpe:2.3:a:cacti:cacti:1.2.13:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cacti:cacti:1.2.13:*:*:*:*:*:*:*
- (no CPE)range: <1.2.14
Patches
Vulnerability mechanics
References
4- github.com/Cacti/cacti/commit/39458efcd5286d50e6b7f905fedcdc1059354e6envdPatchThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdExploitIssue TrackingPatchThird Party Advisory
- github.com/Cacti/cacti/issues/3723nvdExploitIssue TrackingThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/12/msg00039.htmlnvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.