Sploitus

CVE-2020-7237

No indexed exploits for CVE-2020-7237 yet

Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation.php. OS commands are executed when a new poller cycle begins. The attacker must be authenticated, and must have access to modify the Performance Settings of the product.

Affected products
Alt Linux, Cacti, Suse
Cacti
= 1.2.8
Fix
Available
CVSS 2.0
9.0 HIGH
CVSS 3.1
8.8 HIGH
EPSS
36.8% (98th percentile)
Weakness
CWE-78
NVD status
Modified
Published
2020-01-20
CVE-2020-7237 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2020-7237 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2020-7237 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.