Known CVE
Cacti - Cross-Site Scripting
Cacti contains a cross-site scripting vulnerability via "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" which can successfully execute the JavaScript payload present in the "ref" URL parameter.
CVE-2021-26247
Medium2021CVSS 6.1CWE-79
cve2021 · cacti · xss · vuln
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website