CVE detail
CVE-2021-26247 — CVE-2021-26247
Published 2022-01-19 · Modified 2026-06-17 · Vendor cacti · Product cacti · Source nvd
MEDIUM
severity
CVSS-derived band
0.0712
EPSS probability
exploitation probability, 30d
94.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" to successfully execute the JavaScript payload present in the "ref" URL parameter.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References