CVE-2017-5473: CSRF
Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary users, as demonstrated by admin/adduser.lua, admin/changeuserprefs.lua, admin/deleteuser.lua, and admin/passwordreset.lua.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5473?
CVE-2017-5473 is considered a moderate severity vulnerability due to the potential for remote attackers to hijack user authentication.
How do I fix CVE-2017-5473?
To fix CVE-2017-5473, you should upgrade ntopng to version 2.5 or later where the vulnerability has been addressed.
What type of vulnerability is CVE-2017-5473?
CVE-2017-5473 is classified as a cross-site request forgery (CSRF) vulnerability.
Who is affected by CVE-2017-5473?
Users of ntopng version 2.4 and earlier are affected by CVE-2017-5473.
What can attackers do with CVE-2017-5473?
Attackers can utilize CVE-2017-5473 to hijack the authentication of arbitrary users, leading to unauthorized access.