UBUNTU-CVE-2020-14295
Advisory lineage Upstream: 1 Downstream: 1
Upstream
Downstream
Published: 17 Jun 2020, 14:15
Last modified:04 Feb 2026, 03:33
Vulnerability Summary
Overall Risk (default)
medium
29/100 CVSS Score
7.2 HIGH
3.1 (osv_ubuntu)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
17 Jun 2020, 14:15
Published
Vulnerability first disclosed
04 Feb 2026, 03:33
Last Modified
Vulnerability information updated
Description
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries.
CVSS Metrics
- v3.1•HIGH•Score: 7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Systems
- ubuntu•cacti
all | < 1.1.38+ds1-1ubuntu0.1~esm1 | < 1.2.10+ds1-1ubuntu1+esm1