First published: Tue Aug 22 2023(Updated: )
A reflected cross-site scripting (XSS) vulnerability in Cacti 0.8.7g and earlier allows unauthenticated remote attackers to inject arbitrary web script or HTML in the "ref" parameter at auth_changepassword.php.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cacti Cacti | <=0.8.7g |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Cacti vulnerability is CVE-2022-48547.
The severity of CVE-2022-48547 is medium.
The vulnerability in Cacti 0.8.7g and earlier allows unauthenticated remote attackers to inject arbitrary web script or HTML in the 'ref' parameter at auth_changepassword.php.
An attacker can exploit the reflected cross-site scripting (XSS) vulnerability in Cacti 0.8.7g by injecting arbitrary web script or HTML in the 'ref' parameter at auth_changepassword.php.
Yes, you can find more information on CVE-2022-48547 at the following link: [https://github.com/Cacti/cacti/issues/1882](https://github.com/Cacti/cacti/issues/1882)