S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-26247 Scanner

CVE-2021-26247 scanner - Cross-Site Scripting (XSS) vulnerability in Cacti

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
6.1
CVSS
Description

As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" to successfully execute the JavaScript payload present in the "ref" URL parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Cactiby n/a
0.8.7g
Updated Sep 18, 2026View on NVD →
Detail

Cacti is a widely-used network monitoring tool that enables network administrators to gain insights into the performance of various network devices and applications. This open-source software provides them with real-time statistics and graphs, helping them to make informed decisions about their network infrastructure. Cacti's user-friendly interface and comprehensive range of features make it a popular choice for organizations of all sizes and industries.

However, like any software, Cacti is not immune to vulnerabilities. One such vulnerability is CVE-2021-26247, a cross-site scripting (XSS) flaw that was discovered in the auth_changepassword.php script. This vulnerability allows an unauthenticated attacker to inject arbitrary HTML or JavaScript code into the "ref" URL parameter, which can then be executed by unsuspecting users who follow the link.

When this vulnerability is exploited, it can lead to serious consequences for the affected organization. For instance, the attacker may be able to steal sensitive information such as user credentials or access sensitive files or databases. They may also be able to launch further attacks against the organization's network or use the compromised devices as a springboard for attacks against other targets.

In conclusion, it is crucial for organizations that use Cacti to be aware of the CVE-2021-26247 vulnerability and take appropriate precautions to protect against it. Thanks to the pro features of the s4e.io platform, it is easy for security professionals and network administrators to stay up-to-date with the latest vulnerabilities in their digital assets and take proactive measures to mitigate the risks. By staying vigilant and informed, organizations can keep their networks safe from cyber attacks and ensure their continued success.

 

REFERENCES

Solution Advice

Fortunately, there are several precautions that organizations can take to protect themselves against this vulnerability:

  • Apply the latest security patches and updates as soon as they become available
  • Use a web application firewall (WAF) to block known XSS attacks
  • Implement strict input validation and output encoding to prevent malicious code injection
  • Use HTTPS encryption to secure communications between the Cacti server and client devices
  • Regularly audit the Cacti server and network devices for signs of compromise or unusual activity

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.