auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.
References
Information
Published : 2016-04-13 10:59
Updated : 2018-10-30 09:27
NVD link : CVE-2016-2313
Mitre link : CVE-2016-2313
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
opensuse
- opensuse
- leap
cacti
- cacti