CVE Vulnerabilities

CVE-2015-8368

Published: Dec 17, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parameter to admin/password_reset.lua.

Affected Software

NameVendorStart VersionEnd Version
NtopngNtop*2.0.151021 (including)
NtopngUbuntuupstream*
NtopngUbuntuvivid*
NtopngUbuntuwily*

References