Bug 1218380 (CVE-2023-50250)

Summary: VUL-0: CVE-2023-50250: cacti: reflected XSS in templates_import.php via xml upload
Product: [openSUSE] openSUSE Distribution Reporter: SMASH SMASH <smash_bz>
Component: SecurityAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: Andreas.Stieger, meissner, pstivanin
Version: Leap 15.6   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/389224/
Whiteboard:
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description SMASH SMASH 2023-12-24 08:54:00 UTC
Cacti is an open source operational monitoring and fault management framework. A reflection cross-site scripting vulnerability was discovered in version 1.2.25. Attackers can exploit this vulnerability to perform actions on behalf of other users. The vulnerability is found in `templates_import.php.` When uploading an xml template file, if the XML file does not pass the check, the server will give a JavaScript pop-up prompt, which contains unfiltered xml template file name, resulting in XSS. An attacker exploiting this vulnerability could execute actions on behalf of other users. This ability to impersonate users could lead to unauthorized changes to settings. As of time of publication, no patched versions are available.


References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-50250
Comment 1 Andreas Stieger 2023-12-24 13:10:53 UTC
*** Bug 1218358 has been marked as a duplicate of this bug. ***
Comment 2 Andreas Stieger 2023-12-24 13:16:44 UTC
submitted
Comment 3 OBSbugzilla Bot 2023-12-24 15:35:05 UTC
This is an autogenerated message for OBS integration:
This bug (1218380) was mentioned in
https://build.opensuse.org/request/show/1134986 Factory / cacti
https://build.opensuse.org/request/show/1134987 Backports:SLE-12+Backports:SLE-15-SP4+Backports:SLE-15-SP5 / cacti+cacti-spine
Comment 4 OBSbugzilla Bot 2023-12-31 21:35:07 UTC
This is an autogenerated message for OBS integration:
This bug (1218380) was mentioned in
https://build.opensuse.org/request/show/1135899 Backports:SLE-12+Backports:SLE-15-SP5 / cacti+cacti-spine
Comment 5 Marcus Meissner 2024-01-24 17:05:06 UTC
openSUSE-SU-2024:0031-1: An update that fixes 6 vulnerabilities is now available.

Category: security (important)
Bug References: 1218360,1218366,1218378,1218379,1218380,1218381
CVE References: CVE-2023-49084,CVE-2023-49085,CVE-2023-49086,CVE-2023-49088,CVE-2023-50250,CVE-2023-51448
JIRA References: 
Sources used:
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    cacti-1.2.26-38.1, cacti-spine-1.2.26-32.1
Comment 6 Marcus Meissner 2024-01-24 17:05:36 UTC
openSUSE-SU-2024:0031-1: An update that fixes 6 vulnerabilities is now available.

Category: security (important)
Bug References: 1218360,1218366,1218378,1218379,1218380,1218381
CVE References: CVE-2023-49084,CVE-2023-49085,CVE-2023-49086,CVE-2023-49088,CVE-2023-50250,CVE-2023-51448
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP5 (src):    cacti-1.2.26-bp155.2.6.1, cacti-spine-1.2.26-bp155.2.6.1
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    cacti-1.2.26-38.1, cacti-spine-1.2.26-32.1
Comment 7 Andreas Stieger 2024-01-24 17:27:35 UTC
done