{"id":"CVE-2016-10700","details":"auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database, because the guest user is not considered. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-2313.","modified":"2026-07-08T12:43:17.973384Z","published":"2017-11-24T05:29:00.190Z","references":[{"type":"WEB","url":"http://bugs.cacti.net/view.php?id=2697"},{"type":"REPORT","url":"http://www.cacti.net/release_notes_1_0_0.php"},{"type":"REPORT","url":"https://web.archive.org/web/20160817090458/http://bugs.cacti.net/view.php?id=2697"},{"type":"FIX","url":"https://github.com/Cacti/cacti/commit/69983495cd41bf0903fe02baeef84b1fa85f2846"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cacti/cacti","events":[{"introduced":"0"},{"fixed":"de276dec9259e1776a7d60e258a075bf8efa5ed3"},{"fixed":"69983495cd41bf0903fe02baeef84b1fa85f2846"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.0.0"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-10700.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}