SQL injection in Cacti - CVE-2020-14295
Published: July 26, 2020 / Updated: June 20, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data passed via the filter parameter to color.php script. A remote authenticated attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.
Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.
Affected software
Gentoo Linux
Fedora
SUSE Linux
Opensuse
cacti (Alpine package)
cacti
cacti-spine
mbedtls
SUSE Package Hub for SUSE Linux Enterprise
How to mitigate CVE-2020-14295
cacti - addressed in versions 1.2.13-1.el8, 1.2.13-1.fc31, 1.2.13-1.fc32
cacti-spine - addressed in versions 1.2.13-1.el8, 1.2.13-1.fc31, 1.2.13-1.fc32
mbedtls - update to 2.16.7-1.fc32
Links to Public Exploits and PoC-codes
- Exploit #7316 - CVE-2020-14295 (Proof of Concept for CVE-2020-14295.) (February 1, 2022)
- Exploit #5586 - Cacti 1.2.12 - 'filter' SQL Injection / Remote Code Execution (June 17, 2021)
- Exploit #5508 - Cacti color filter authenticated SQLi to RCE (June 1, 2021)
- Exploit #5504 - poc-CVE-2020-14295 (Proof of Concept for CVE-2020-14295.) (May 30, 2021)
- Exploit #5328 - CVE-2020-14295 (Authenticated SQL injection to command execution on Cacti 1.2.12 ) (April 30, 2021)
External References
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.html
- https://github.com/Cacti/cacti/issues/3622
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W64CIB6L4HZRVQSWKPDDKXJO4J2XTOXD/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKM5G3YNSZDHDZMPCMAHG5B5M2V4XYSE/
- https://github.com/Cacti/cacti/blob/release/1.2.13/CHANGELOG
- https://github.com/Cacti/cacti/security/advisories/GHSA-rwgg-5vv3-4hxp
Related Security Bulletins
- OpenSUSE Linux update for cacti, cacti-spine
- OpenSUSE Linux update for cacti, cacti-spine
- Multiple vulnerabilities in Cacti
- Gentoo update for Cacti
- OpenSUSE Linux update for cacti, cacti-spine
- SQL injection in cacti (Alpine package)
- Fedora EPEL 8 update for cacti, cacti-spine
- Fedora 31 update for cacti, cacti-spine
- Fedora 32 update for cacti, cacti-spine
- Fedora 32 update for mbedtls