\" to successfully execute the JavaScript payload present in the \"ref\" URL parameter.","datePublished":"2022-01-19T20:38:53+00:00","dateModified":"2024-08-03T20:19:20.307000+00:00","inLanguage":"en","author":{"@type":"Organization","name":"Vexday"},"publisher":{"@type":"Organization","name":"Vexday","url":"https://vexday.io"},"mainEntityOfPage":"https://vexday.io/en/cve/CVE-2021-26247","keywords":"CVE-2021-26247, CWE-79","breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://vexday.io/en"},{"@type":"ListItem","position":2,"name":"CVE-2021-26247"}]}}← back
CVE-2021-26247CWE-79

CVE-2021-26247

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 7.1%
exploitation probability
7.1%top 6% of all CVEs
observed exploitation
nono source reports it
As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" to successfully execute the JavaScript payload present in the "ref" URL parameter.
Affected products
n/a · Cacti