CVE-2021-26247
MEDIUM NUCLEICacti - Unauthenticated Stored Cross-Site Scripting via Ref URL Parameter
Title source: llmExploitation Summary
CVE-2021-26247 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.
Description
As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" to successfully execute the JavaScript payload present in the "ref" URL parameter.
Nuclei Templates (1)
Cacti - Cross-Site Scripting
MEDIUMby dhiyaneshDK
Shodan:
http.title:"login to cacti" || http.title:"cacti" || http.favicon.hash:"-1797138069"
FOFA:
icon_hash="-1797138069" || title="cacti" || title="login to cacti"
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://www.cacti.net/info/changelog
Scores
CVSS v3
6.1
EPSS
0.0712
EPSS Percentile
93.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
cacti/cacti
0.8.7g
Published
Jan 19, 2022
Tracked Since
Feb 18, 2026