ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.
{ "binaries": [ { "binary_version": "2.2+dfsg1-1ubuntu0.1~esm2", "binary_name": "ntopng" }, { "binary_version": "2.2+dfsg1-1ubuntu0.1~esm2", "binary_name": "ntopng-data" } ] }
{ "binaries": [ { "binary_version": "5.2.1+dfsg1-1", "binary_name": "ntopng" }, { "binary_version": "5.2.1+dfsg1-1", "binary_name": "ntopng-data" } ] }