CVE-2021-26247

MEDIUM NUCLEI

Cacti - Unauthenticated Stored Cross-Site Scripting via Ref URL Parameter

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-26247 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" to successfully execute the JavaScript payload present in the "ref" URL parameter.

Nuclei Templates (1)

Cacti - Cross-Site Scripting
MEDIUMby dhiyaneshDK
Shodan: http.title:"login to cacti" || http.title:"cacti" || http.favicon.hash:"-1797138069"
FOFA: icon_hash="-1797138069" || title="cacti" || title="login to cacti"

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://www.cacti.net/info/changelog

Scores

CVSS v3 6.1
EPSS 0.0712
EPSS Percentile 93.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
cacti/cacti 0.8.7g
Published Jan 19, 2022
Tracked Since Feb 18, 2026