Cross-site scripting (XSS) vulnerability in aggregategraphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancelurl variable.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-11163.json"