Loading
In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() allows a zero as the password.
Use CWE-863, Cacti vendor hub and Cacti product page to widen CVE-2022-48538 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-22604, CVE-2005-10004 and CVE-2025-24367 for nearby disclosures in the same product family.