CVE-2017-7416 (NVD)

2017-06-26

ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.

Products Ntopng
Type Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79)
First patch - None (likely due to unavailable code)
Links https://github.com/ntop/ntopng/blob/3.0/CHANGELOG.md