5.3 Medium
AI Score
Confidence
High
0.001 Low
EPSS
Percentile
20.2%
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable.
www.securitytracker.com/id/1038908
github.com/Cacti/cacti/issues/847