Cross-Site Scripting in ntopng Products by ntop
CVE-2017-7416

6.1MEDIUM

Key Information:

Vendor

Ntop

Status
Vendor
CVE Published:
26 June 2017

What is CVE-2017-7416?

A cross-site scripting vulnerability exists in ntopng versions prior to 3.0, which allows attackers to inject malicious scripts via improperly validated GET and POST parameters. This could lead to the execution of arbitrary JavaScript in the context of the user's browser, potentially compromising sensitive user data or session tokens.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.