CVE-2022-48547: XSS
A reflected cross-site scripting (XSS) vulnerability in Cacti 0.8.7g and earlier allows unauthenticated remote attackers to inject arbitrary web script or HTML in the "ref" parameter at authchangepassword.php.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Cacti vulnerability?
The vulnerability ID for this Cacti vulnerability is CVE-2022-48547.
What is the severity of CVE-2022-48547?
The severity of CVE-2022-48547 is medium.
How does the vulnerability in Cacti 0.8.7g and earlier affect the software?
The vulnerability in Cacti 0.8.7g and earlier allows unauthenticated remote attackers to inject arbitrary web script or HTML in the 'ref' parameter at auth_changepassword.php.
How can an attacker exploit the reflected cross-site scripting (XSS) vulnerability in Cacti 0.8.7g?
An attacker can exploit the reflected cross-site scripting (XSS) vulnerability in Cacti 0.8.7g by injecting arbitrary web script or HTML in the 'ref' parameter at auth_changepassword.php.
Are there any references available for more information on CVE-2022-48547?
Yes, you can find more information on CVE-2022-48547 at the following link: [https://github.com/Cacti/cacti/issues/1882](https://github.com/Cacti/cacti/issues/1882)