CVE-2025-45160

Source
https://cve.org/CVERecord?id=CVE-2025-45160
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-45160.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-45160
Downstream
Published
2026-01-29T18:16:07.693Z
Modified
2026-04-10T05:27:02.243713Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A HTML injection vulnerability exists in the file upload functionality of Cacti <= 1.2.29. When a file with an invalid format is uploaded, the application reflects the submitted filename back into an error popup without proper sanitization. As a result, attackers can inject arbitrary HTML elements (e.g., <h1>, <b>, <svg>) into the rendered page. NOTE: Multiple third-parties including the maintainer have stated that they cannot reproduce this issue after 1.2.27.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-45160.json"