Cacti could allow a remote attacker to conduct phishing attacks, caused by an error in graph_settings.php script. A remote attacker could exploit this vulnerability using the referer parameter in a specially-crafted URL to redirect a victim to arbitrary Web sites.