Debian Security Advisory 1569-2 – The original update for cacti unfortunately introduced a regression. Updated packages have been created to address this. It was discovered that Cacti, a systems and services monitoring frontend, performed insufficient input sanitising, leading to cross site scripting and SQL injection being possible.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/66033/dsa-1569-2.txt
Source: https://packetstormsecurity.com/files/66033/Debian-Linux-Security-Advisory-1569-2.html

