CVE-2020-35701: SQL Injection
An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerability in datadebug.php allows remote authenticated attackers to execute arbitrary SQL commands via the siteid parameter. This can lead to remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-35701?
CVE-2020-35701 is a SQL injection vulnerability in Cacti 1.2.x through 1.2.16.
How does CVE-2020-35701 affect Cacti?
CVE-2020-35701 allows remote authenticated attackers to execute arbitrary SQL commands via the site_id parameter.
What is the severity of CVE-2020-35701?
CVE-2020-35701 has a severity rating of 8.8 (high).
How can I fix CVE-2020-35701?
To fix CVE-2020-35701, users should update to Cacti version 1.2.17 or later.
Where can I find more information about CVE-2020-35701?
More information about CVE-2020-35701 can be found in the references provided: [Link 1](https://asaf.me/2020/12/15/cacti-1-2-0-to-1-2-16-sql-injection/), [Link 2](https://github.com/Cacti/cacti/issues/4022), [Link 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6DDD22Z56THHDTXAFM447UH3BVINURIF/).