High severity8.8NVD Advisory· Published Apr 13, 2016· Updated May 6, 2026
CVE-2016-2313
CVE-2016-2313
Description
auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.
Affected products
4Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- bugs.cacti.net/view.phpnvd
- lists.opensuse.org/opensuse-updates/2016-02/msg00077.htmlnvd
- lists.opensuse.org/opensuse-updates/2016-02/msg00078.htmlnvd
- lists.opensuse.org/opensuse-updates/2016-02/msg00080.htmlnvd
- www.cacti.net/release_notes_0_8_8g.phpnvd
- www.securitytracker.com/id/1037745nvd
- security.gentoo.org/glsa/201607-05nvd
- security.gentoo.org/glsa/201711-10nvd
News mentions
0No linked articles in our index yet.