CVE-2020-7237: OS Command Injection
Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of pollerautomation.php. OS commands are executed when a new poller cycle begins. The attacker must be authenticated, and must have access to modify the Performance Settings of the product.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7237?
CVE-2020-7237 is a vulnerability in Cacti 1.2.8 that allows remote code execution by privileged users via shell metacharacters.
What is the severity of CVE-2020-7237?
CVE-2020-7237 has a severity rating of 8.8 (Critical).
How does CVE-2020-7237 allow remote code execution?
CVE-2020-7237 allows remote code execution by using shell metacharacters in the Performance Boost Debug Log field of poller_automation.php.
Who can exploit CVE-2020-7237?
Only privileged users who are authenticated and have access to modify the Performance Settings can exploit CVE-2020-7237.
How can I fix CVE-2020-7237?
To fix CVE-2020-7237, update Cacti to version 1.2.9 or later.