Cacti · Cacti · CVE-2022-48547
**Name of the Vulnerable Software and Affected Versions**
Cacti versions 0.8.7g and earlier
**Description**
A reflected cross-site scripting (XSS) vulnerability allows unauthenticated remote attackers to inject arbitrary web script or HTML in the `ref` parameter at "auth changepassword.php". This issue is related to the lack of protection of the web page structure, which can be exploited by a remote attacker to conduct a cross-site scripting (XSS) attack.
**Recommendations**
For Cacti versions 0.8.7g and earlier, as a temporary workaround, consider restricting access to the "auth changepassword.php" page until a patch is available. Avoid using the `ref` parameter in the affected page to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.