Summary
Cacti is prone to multiple multiple input-validation vulnerabilities including:
1. Multiple cross-site scripting vulnerabilities.
2. A cross-site request-forgery vulnerability.
3. An HTML-injection vulnerability.
An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, disclose or modify sensitive information, or perform unauthorized actions. Other attacks are also possible.
Versions prior to Cacti 0.8.7i are vulnerable.
Solution
Updates are available. Please see the references for more information.
References