First published: Mon Jan 11 2021(Updated: )
An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerability in data_debug.php allows remote authenticated attackers to execute arbitrary SQL commands via the site_id parameter. This can lead to remote code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cacti | >=1.2.0<=1.2.16 | |
Fedora | =32 | |
Fedora | =33 | |
Fedora | =34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35701 is a SQL injection vulnerability in Cacti 1.2.x through 1.2.16.
CVE-2020-35701 allows remote authenticated attackers to execute arbitrary SQL commands via the site_id parameter.
CVE-2020-35701 has a severity rating of 8.8 (high).
To fix CVE-2020-35701, users should update to Cacti version 1.2.17 or later.
More information about CVE-2020-35701 can be found in the references provided: [Link 1](https://asaf.me/2020/12/15/cacti-1-2-0-to-1-2-16-sql-injection/), [Link 2](https://github.com/Cacti/cacti/issues/4022), [Link 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6DDD22Z56THHDTXAFM447UH3BVINURIF/).