← back
CVE-2020-14295

CVE-2020-14295

60Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 86%
from disclosure to weapon315 days
Published on NVDJun 17
1st PoC+315d
metasploitJun 17
exploitation probability
86%top 1% of all CVEs
observed exploitation
nono source reports it
5 public exploit(s)
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.