{"id":"CVE-2017-5473","details":"Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary users, as demonstrated by admin/add_user.lua, admin/change_user_prefs.lua, admin/delete_user.lua, and admin/password_reset.lua.","modified":"2026-07-08T12:28:25.395537Z","published":"2017-01-14T07:59:00.183Z","references":[{"type":"WEB","url":"https://www.exploit-db.com/exploits/41141/"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/95654"},{"type":"FIX","url":"https://github.com/ntop/ntopng/commit/1b2ceac8f578a246af6351c4f476e3102cdf21b3"},{"type":"FIX","url":"https://github.com/ntop/ntopng/commit/f91fbe3d94c8346884271838ae3406ae633f6f15"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ntop/ntopng","events":[{"introduced":"0"},{"last_affected":"3e0705528bb8322f67b1b9d2a2476f5294ae0ca8"},{"fixed":"1b2ceac8f578a246af6351c4f476e3102cdf21b3"},{"fixed":"f91fbe3d94c8346884271838ae3406ae633f6f15"}],"database_specific":{"cpe":"cpe:2.3:a:ntop:ntopng:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"2.4"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["2.4"],"database_specific":{"vanir_signatures_modified":"2026-07-08T12:28:25Z","vanir_signatures":[{"id":"CVE-2017-5473-b0719f94","signature_type":"Function","signature_version":"v1","source":"https://github.com/ntop/ntopng/commit/f91fbe3d94c8346884271838ae3406ae633f6f15","target":{"file":"src/Lua.cpp","function":"Lua::handle_script_request"},"deprecated":false,"digest":{"function_hash":"71848155384282004662442714532844800224","length":4392}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/ntop/ntopng/commit/f91fbe3d94c8346884271838ae3406ae633f6f15","target":{"file":"src/Lua.cpp"},"deprecated":false,"digest":{"line_hashes":["225890363715307453550239920584568499817","25522932087144486915853405681340136863","16451836396933530035953238867708917385","36658721762314712032031679741911206814","161559272232410082750223943058809649339","288821002058907882668376211981812315616","207965429719056115887668198102794801962","86456144177509764090143768108223181688","968914550610708735454144030686582828","267444822828386139284651165522848858289","93008527089901331249203990404599678449","318641026629784019067788098929129842588","184689117743268875215430833870074659190","307035981538322759458769642686153788608","213199330918513964045691524369345204292","94623068172622676134704117487809010877","239999661867838851691592948118280526972"],"threshold":0.9},"id":"CVE-2017-5473-c86f0333"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-5473.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}