Bugzilla – Bug 1194868
VUL-0: CVE-2021-26247: cacti: XSS allows an unauthenticated remote attackers to perform HTML injection
Last modified: 2022-01-19 09:18:45 UTC
rh#2042292 As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" to successfully execute the JavaScript payload present in the "ref" URL parameter. Upstream commit: https://github.com/Cacti/cacti/commit/2b8097c06030ab72c5b3bdadb23dceb5332f0e94 References: https://github.com/Cacti/cacti/issues/1882 https://www.cacti.net/info/changelog https://bugzilla.redhat.com/show_bug.cgi?id=2042292 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-26247
Fixing commit is the same as bnc#1194860, therefore this is also already fixed.