Related Vulnerabilities: CVE-2017-11691  

A cross-site scripting vulnerability has been found in Cacti <= 1.1.13, in the user profile management page (auth_profile.php), allowing inject arbitrary web script or HTML via specially crafted HTTP Referer headers.

Severity Medium

Remote Yes

Type Cross-site scripting

Description

A cross-site scripting vulnerability has been found in Cacti <= 1.1.13, in the user profile management page (auth_profile.php), allowing inject arbitrary web script or HTML via specially crafted HTTP Referer headers.

AVG-365 cacti 1.1.13-1 1.1.14-1 Medium Fixed

27 Jul 2017 ASA-201707-30 AVG-365 cacti Medium cross-site scripting

http://seclists.org/oss-sec/2017/q3/217
https://github.com/Cacti/cacti/issues/867
https://github.com/Cacti/cacti/commit/104090aeead4aa433bf1f18cd6d52dcfeb71236c