CVE-2020-14295

HIGH7.2EPSS 78.7%
Published: 6/17/2020Modified: 5/27/2026
Also known as:DEBIAN-CVE-2020-14295

Description

A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

References (1)