CVE-2020-8813: OS Command Injection
graphrealtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2020-8813.
What is the severity of CVE-2020-8813?
CVE-2020-8813 has a severity level of critical (8.8).
How does CVE-2020-8813 allow remote attackers to execute arbitrary OS commands?
CVE-2020-8813 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege.
Which software versions are affected by CVE-2020-8813?
The software versions affected by CVE-2020-8813 are Cacti 1.2.8, Fedoraproject Fedora 30, Fedoraproject Fedora 31, Fedoraproject Fedora 32, Opmantek Open-AudIT 3.3.1, Opensuse Suse Package Hub, and Debian Debian Linux 10.0.
How can I fix CVE-2020-8813?
To fix CVE-2020-8813, it is recommended to upgrade to a patched version of the affected software.