CVE-2017-5473
HIGHntopng < 2.4 - Cross-Site Request Forgery via User Management Endpoints
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-5473. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This exploit demonstrates a CSRF token bypass vulnerability in ntopng Web Interface v2.4.160627, allowing remote attackers to perform actions like password resets and user additions on behalf of authenticated users by omitting or supplying arbitrary CSRF tokens.
Description
Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary users, as demonstrated by admin/add_user.lua, admin/change_user_prefs.lua, admin/delete_user.lua, and admin/password_reset.lua.
Exploits (1)
This exploit demonstrates a CSRF token bypass vulnerability in ntopng Web Interface v2.4.160627, allowing remote attackers to perform actions like password resets and user additions on behalf of authenticated users by omitting or supplying arbitrary CSRF tokens.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H