Debian LTS: DLA-3252-1: cacti security update
Summary
Askar discovered that an authenticated guest user with the graph
real-time privilege could execute arbitrary code on a server running
Cacti, via shell meta-characters in a cookie.
CVE-2020-23226
Jing Chen discovered multiple Cross Site Scripting (XSS)
vulnerabilities in several pages, which can lead to information
disclosure.
CVE-2020-25706
joelister discovered an Cross Site Scripting (XSS) vulnerability in
templates_import.php, which can lead to information disclosure.
CVE-2022-0730
It has been discovered that Cacti authentication can be bypassed
when LDAP anonymous binding is enabled.
CVE-2022-46169
Stefan Schiller discovered a command injection vulnerability,
allowing an unauthenticated user to execute arbitrary code on a
server running Cacti, if a specific data source was selected (which
is likely the case on a production instance) for any monitored
device.
For Debian 10 buster, these problems have been fixed in version
1.2.2+ds1-2+deb10u5.
...