#VU31877 Cross-site request forgery in Cacti - CVE-2020-13231
Published: July 26, 2020
Cacti
The Cacti Group, Inc.
Description
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to insufficient validation of the HTTP request origin in auth_profile.php?action=edit. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website, such as changing data in victim's profile.
Remediation
External links
- https://github.com/Cacti/cacti/issues/3342
- https://github.com/Cacti/cacti/releases/tag/release%2F1.2.11
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ICJMWSY77IIGZYR6FE6NAQZFBO42VECO/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q3PCDGNELH7HEBIXRNT5J5EWQEXQAU6B/