Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary users, as demonstrated by admin/adduser.lua, admin/changeuserprefs.lua, admin/deleteuser.lua, and admin/password_reset.lua.
[
{
"digest": {
"length": 4392.0,
"function_hash": "71848155384282004662442714532844800224"
},
"id": "CVE-2017-5473-b0719f94",
"source": "https://github.com/ntop/ntopng/commit/f91fbe3d94c8346884271838ae3406ae633f6f15",
"signature_type": "Function",
"target": {
"file": "src/Lua.cpp",
"function": "Lua::handle_script_request"
},
"signature_version": "v1",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"225890363715307453550239920584568499817",
"25522932087144486915853405681340136863",
"16451836396933530035953238867708917385",
"36658721762314712032031679741911206814",
"161559272232410082750223943058809649339",
"288821002058907882668376211981812315616",
"207965429719056115887668198102794801962",
"86456144177509764090143768108223181688",
"968914550610708735454144030686582828",
"267444822828386139284651165522848858289",
"93008527089901331249203990404599678449",
"318641026629784019067788098929129842588",
"184689117743268875215430833870074659190",
"307035981538322759458769642686153788608",
"213199330918513964045691524369345204292",
"94623068172622676134704117487809010877",
"239999661867838851691592948118280526972"
]
},
"id": "CVE-2017-5473-c86f0333",
"source": "https://github.com/ntop/ntopng/commit/f91fbe3d94c8346884271838ae3406ae633f6f15",
"signature_type": "Line",
"target": {
"file": "src/Lua.cpp"
},
"signature_version": "v1",
"deprecated": false
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-5473.json"