CVE-2020-14295
7.2
HIGH
CVSS 3.1
EPSS 86.3%
Description
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries.
How to fix CVE-2020-14295
To remediate CVE-2020-14295, upgrade the affected package to a fixed version below.
- Debian/cacti—upgrade to 1.2.13+ds1-1 or later
Is CVE-2020-14295 being exploited?
Likely — EPSS is 86.3%, placing CVE-2020-14295 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (1)
- from 0, < 1.2.13+ds1-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.2 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |