First published: Thu Jul 27 2017(Updated: )
Cross-site scripting (XSS) vulnerability in auth_profile.php in Cacti 1.1.13 allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cacti Cacti | =1.1.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-11691 is rated as medium with a score of 5.4.
To fix CVE-2017-11691, update Cacti to version 1.1.14 or later where the vulnerability is addressed.
CVE-2017-11691 is a Cross-site scripting (XSS) vulnerability affecting Cacti version 1.1.13.
Attackers can exploit CVE-2017-11691 to inject arbitrary web scripts or HTML through specially crafted HTTP Referer headers.
Cacti version 1.1.13 is affected by CVE-2017-11691.