CVE-2020-14295
7.2
HIGH
CVSS 3.1
EPSS 78.7%
Description
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries.
How to fix CVE-2020-14295
To remediate CVE-2020-14295, upgrade the affected package to a fixed version below.
- Debian/cacti—upgrade to 1.2.13+ds1-1 or later
Is CVE-2020-14295 being exploited?
Likely — EPSS is 78.7%, placing CVE-2020-14295 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (1)
- from 0, < 1.2.13+ds1-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.2 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |