CVE-2020-13230: Cacti
Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.
In Cacti before 1.2.11, disabling a user account does not immediately invalidate any permissions granted to that account (e.g., permission to view logs).
Affected products
- Cacti Cacti: before 1.2.11 (fixed in 1.2.11)
- Debian Debian Linux: version 9.0 only
- Fedoraproject Fedora: version 31 only; version 32 only
Published 2020-05-20. Last modified 2026-06-17.