ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parameter to admin/password_reset.lua.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "ntopng",
"binary_version": "2.2+dfsg1-1build1"
},
{
"binary_name": "ntopng-data",
"binary_version": "2.2+dfsg1-1build1"
},
{
"binary_name": "ntopng-dbg",
"binary_version": "2.2+dfsg1-1build1"
},
{
"binary_name": "ntopng-dbgsym",
"binary_version": "2.2+dfsg1-1build1"
}
]
}