ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parameter to admin/password_reset.lua.
{ "urgency": "not yet assigned" }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2015-8368.json"