6.8
CVSSv2

CVE-2017-5473

Published: 14/01/2017 Updated: 02/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in ntopng up to and including 2.4 allows remote malicious users to hijack the authentication of arbitrary users, as demonstrated by admin/add_user.lua, admin/change_user_prefs.lua, admin/delete_user.lua, and admin/password_reset.lua.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ntop ntopng

Vendor Advisories

Debian Bug report logs - #852109 ntopng: CVE-2017-5473 Package: ntopng; Maintainer for ntopng is Ludovico Cavedon <cavedon@debianorg>; Source for ntopng is src:ntopng (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Sat, 21 Jan 2017 18:15:02 UTC Severity: grave Tags: security, upstream ...

Exploits

[+]##################################################################################### [+] Credits / Discovery: John Page AKA Hyp3rlinX [+] Website: hyp3rlinxaltervistaorg [+] Source: hyp3rlinxaltervistaorg/advisories/NTOPNG-CSRF-TOKEN-BYPASStxt [+] ISR: ApparitionSEC [+]################################################################ ...
ntopng Web Interface version 24160627 suffers from a cross site request forgery token bypass vulnerability ...