USN-5214-1

    Dashboard / Vulnerabilities / USN-5214-1

    USN-5214-1

    Published: 9 Jun 2022Last Modified: 25 Jun 2026

    Summary: cacti vulnerabilities

    Details: It was discovered that Cacti was incorrectly validating permissions for user accounts that had been recently disabled. An authenticated attacker could possibly use this to obtain unauthorized access to application and system data. (CVE-2020-13230) It was discovered that Cacti was incorrectly performing authorization checks in auth_profile.php. A remote unauthenticated attacker could use this to perform a CSRF attack and set a new admin email or make other changes. This issue only affected Ubuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2020-13231) It was discovered that Cacti incorrectly handled user provided input sent through request parameters to the color.php script. A remote authenticated attacker could use this issue to perform SQL injection attacks. This issue only affected Ubuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2020-14295) It was discovered that Cacti did not properly escape file input fields when performing template import operations for various themes. An authenticated attacker could use this to perform XSS attacks. This issue only affected Ubuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2020-14424) It was discovered that Cacti incorrectly handled user provided input sent through request parameters to the data_debug.php script. A remote authenticated attacker could use this issue to perform SQL injection attacks. This issue only affected Ubuntu 20.04 ESM. (CVE-2020-35701)

    Affected packages

    Package

    Name: cacti

    Purl: pkg:deb/ubuntu/cacti?arch=source&distro=esm-apps%2Fxenial

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.8.8f+ds1-4ubuntu4.16.04.2+esm1

    Affected versions

    0.8.8f+ds1-2
    0.8.8f+ds1-3
    0.8.8f+ds1-4
    0.8.8f+ds1-4ubuntu1
    0.8.8f+ds1-4ubuntu2
    0.8.8f+ds1-4ubuntu3
    0.8.8f+ds1-4ubuntu4
    0.8.8f+ds1-4ubuntu4.16.04
    0.8.8f+ds1-4ubuntu4.16.04.1
    0.8.8f+ds1-4ubuntu4.16.04.2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    USN-5214-1 | CVE-DB