Security Advisory
CVE-2015-8368
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parameter to admin/password_reset.lua.