NA

CVE-2022-48538

Published: 22/08/2023 Updated: 28/08/2023
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() allows a zero as the password.

Vulnerable Product Search on Vulmon Subscribe to Product

cacti cacti 1.2.19