CVE-2020-23226
Cacti vulnerability analysis and mitigation

Overview

Multiple Cross Site Scripting (XSS) vulnerabilities were discovered in Cacti version 1.2.12 affecting multiple PHP files including reports_admin.php, data_queries.php, data_input.php, graph_templates.php, graphs.php, and reports_admin.php. The vulnerability was assigned CVE-2020-23226 and was discovered in May 2020 (GitHub Issue).

Technical details

The vulnerability stems from insufficient input validation and output encoding in multiple PHP files within the Cacti application. When exploited, an attacker could inject malicious JavaScript code that would execute in the victim's browser context. The issue was particularly present in various administrative interfaces where user input was not properly sanitized before being displayed back to users (Debian LTS).

Impact

The XSS vulnerabilities could lead to information disclosure and potentially allow attackers to perform actions with the privileges of the victim user. When successfully exploited, the attacker could steal session cookies, capture keystrokes, or perform unauthorized actions on behalf of the authenticated user (Debian Security Tracker).

Mitigation and workarounds

The vulnerability was fixed in subsequent releases of Cacti. Debian released security updates addressing this issue in multiple versions: version 0.8.8h+ds1-10+deb9u2 for Debian 9 (Stretch) and version 1.2.2+ds1-2+deb10u5 for Debian 10 (Buster) (Debian LTS, Debian LTS).

Additional resources


SourceThis report was generated using AI

Related Cacti vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-26520CRITICAL9.8
  • CactiCacti
  • cacti
NoYesFeb 12, 2025
CVE-2005-10004HIGH8.7
  • CactiCacti
  • cacti
NoYesAug 30, 2025
CVE-2025-24367HIGH8.7
  • CactiCacti
  • cacti
NoYesJan 27, 2025
CVE-2025-66399HIGH7.4
  • CactiCacti
  • cacti
NoYesDec 02, 2025
CVE-2025-24368MEDIUM6.9
  • CactiCacti
  • cacti
NoYesJan 27, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management