Cacti · Cacti · CVE-2017-11163
**Name of the Vulnerable Software and Affected Versions**
Cacti version 1.1.12
**Description**
A cross-site scripting (XSS) issue exists, allowing remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the `cancel url` variable.
**Recommendations**
For Cacti version 1.1.12, update to a version that fixes this issue, ensuring that the `cancel url` variable is properly sanitized to prevent XSS attacks.