CVE-2015-8368: Ntop Ntopng
Medium severity, CVSS 6.0. EPSS: 5.1% chance of exploitation in the next 30 days.
ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parameter to admin/password_reset.lua.
Affected products
- Ntop Ntopng: up to and including 2.0.151021
Published 2015-12-17. Last modified 2026-06-17.