High severity7.2NVD Advisory· Published Jun 17, 2020· Updated Jun 17, 2026
CVE-2020-14295
CVE-2020-14295
Description
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14- Cacti/Cactidescription
=1.2.12+ 1 more
- (no CPE)range: =1.2.12
- cpe:2.3:a:cacti:cacti:1.2.12:*:*:*:*:*:*:*
- osv-coords9 versionspkg:rpm/opensuse/cacti&distro=openSUSE%20Tumbleweedpkg:rpm/suse/cacti-spine&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/suse/cacti&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/opensuse/cacti&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/cacti-spine&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/cacti&distro=SUSE%20Package%20Hub%2012pkg:rpm/suse/cacti-spine&distro=SUSE%20Package%20Hub%2012pkg:rpm/opensuse/cacti&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/cacti-spine&distro=openSUSE%20Leap%2015.1
< 1.2.18-1.2+ 8 more
- (no CPE)range: < 1.2.18-1.2
- (no CPE)range: < 1.2.13-bp151.4.12.1
- (no CPE)range: < 1.2.13-bp151.4.12.1
- (no CPE)range: < 1.2.13-11.1
- (no CPE)range: < 1.2.13-8.1
- (no CPE)range: < 1.2.13-11.1
- (no CPE)range: < 1.2.13-8.1
- (no CPE)range: < 1.2.13-11.1
- (no CPE)range: < 1.2.13-8.1
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
8- packetstormsecurity.com/files/162384/Cacti-1.2.12-SQL-Injection-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/162918/Cacti-1.2.12-SQL-Injection-Remote-Command-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- github.com/Cacti/cacti/issues/3622nvdExploitIssue TrackingThird Party Advisory
- security.gentoo.org/glsa/202007-03nvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.htmlnvdBroken Link
- lists.opensuse.org/opensuse-security-announce/2020-07/msg00085.htmlnvdBroken Link
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W64CIB6L4HZRVQSWKPDDKXJO4J2XTOXD/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKM5G3YNSZDHDZMPCMAHG5B5M2V4XYSE/nvd
News mentions
0No linked articles in our index yet.