Exploit for Cacti - Cross-Site Scripting (CVE-2021-26247)
Description:
Cacti contains a cross-site scripting vulnerability via “http:///auth_changepassword.php?ref=" which can successfully execute the JavaScript payload present in the "ref" URL parameter.