CVE-2016-2313
auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.
- Cacti
- β€ 0.8.8f
- CVSS 3.0
- 8.8 HIGH
- EPSS
- 2.7% (85th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2016-04-13
CVE-2016-2313 at NVD
1 known exploit for CVE-2016-2313
Proof-of-concept code and exploit modules indexed by Sploitus