CVE-2015-8368: Medium severity ntopng vulnerability
Published Dec 17, 2015
·Updated
ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parameter to admin/passwordreset.lua.
Affected Software
1 affected component
ntop ntopng<=2.0.151021
Event History
Dec 17, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8368?
CVE-2015-8368 has been rated as a high-severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2015-8368?
You can fix CVE-2015-8368 by upgrading ntopng to version 2.2 or later.
3
What type of vulnerability is CVE-2015-8368?
CVE-2015-8368 is a privilege escalation vulnerability that affects authenticated users.
4
Who is affected by CVE-2015-8368?
Users of ntopng versions prior to 2.2 are vulnerable to CVE-2015-8368 if they are authenticated.
5
What software is impacted by CVE-2015-8368?
CVE-2015-8368 impacts ntopng versions up to and including 2.0.151021.