cbcvebase.
CVE-2015-8368
published 2015-12-17

CVE-2015-8368: ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parameter to…

PriorityP339medium6CVSS 2.0
AVNACMAuSCPIPAP
EXPLOIT
EPSS
5.39%
91.7th percentile
ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parameter to admin/password_reset.lua.

Affected

2 ranges
VendorProductVersion rangeFixed in
ntopntopng<= 2.0.151021
ntopntopng>= 0 < 2.2+dfsg1-12.2+dfsg1-1

CVSS provenance

nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv6.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.