CVE 2018-10059
Cacti before 1.1.37 has XSS because the get_current_page function in lib/functions.php relies on $_SERVER[
See the
CVE page on Mitre.org
for more details.
Cacti before 1.1.37 has XSS because the get_current_page function in lib/functions.php relies on $_SERVER[