lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.
https://github.com/Cacti/cacti/issues/918
https://github.com/Cacti/cacti/commit/9c610a7a4e29595dcaf7d7082134e4b89619ea24
https://github.com/Cacti/cacti/blob/develop/docs/CHANGELOG
http://www.securitytracker.com/id/1039226
Source: Mitre, NVD
Published: 2017-08-21
Updated: 2017-08-27
Base Score: 3.5
Vector: CVSS2#AV:N/AC:M/Au:S/C:N/I:P/A:N
Severity: Low
Base Score: 5.4
Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Severity: Medium