Cacti v1.2.8 is susceptible to remote code execution. This vulnerability could be exploited without authentication if "Guest Realtime Graphs" privileges are enabled.
id: CVE-2020-8813
info:
name: Cacti v1.2.8 - Remote Code Execution
author: gy741
severity: hi
...