CVE-2021-26247: XSS
Published Jan 19, 2022
·Updated
As an unauthenticated remote user, visit "http://<CACTISERVER>/authchangepassword.php?ref=<script>alert(1)</script>" to successfully execute the JavaScript payload present in the "ref" URL parameter.
Affected Software
1 affected component
Cacti Cacti=0.8.7g
Event History
Jan 19, 2022
CVE Published
via MITRE·08:38 PM
Data Sourced
via MITRE·08:38 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-26247.
2
How can I exploit this vulnerability?
To exploit this vulnerability, you can visit the URL "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" as an unauthenticated remote user.
3
What is the severity of CVE-2021-26247?
The severity of CVE-2021-26247 is medium with a CVSS score of 6.1.
4
What versions of Cacti are affected by CVE-2021-26247?
Cacti version 0.8.7g is affected by CVE-2021-26247.
5
How can I fix CVE-2021-26247?
To fix CVE-2021-26247, you should update Cacti to a version that is not affected by the vulnerability.