Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-48547


A reflected cross-site scripting (XSS) vulnerability in Cacti 0.8.7g and earlier allows unauthenticated remote attackers to inject arbitrary web script or HTML in the "ref" parameter at auth_changepassword.php.


Published

2023-08-22T19:16:31.647

Last Modified

2024-11-21T07:33:30.267

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cacti cacti ≤ 0.8.7g Yes

References