← All CVEs

CVE-2020-14295

high · 7.2

A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries.

7.2
CVSS
86.3%
EPSS (exploit prob.)
100th
EPSS percentile
2020-06-17
Published

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-89

Affected products

VendorProductAffected versions
cacticacti1.2.12
fedoraprojectfedora31
fedoraprojectfedora32

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-14295