vendor:
ntopng Web Interface
by:
John Page AKA Hyp3rlinX
8.8
CVSS
HIGH
CSRF Token Bypass
Unknown
CWE
Product Name: ntopng Web Interface
Affected Version From: 2.4.160627
Affected Version To: 2.4.160627
Patch Exists: NO
Related CWE: CVE-2017-5473
CPE: a:ntop:ntopng:2.4.160627
Platforms Tested: Unix, MacOSX, Windows
2017
CSRF Token Bypass in ntopng Web Interface
By omitting or supplying arbitrary CSRF tokens, remote attackers can bypass CSRF protection in the ntopng web interface, allowing them to make HTTP requests on an authenticated user's behalf.
Mitigation:
Unknown