Stored Cross-Site Scripting Vulnerability in PRTG Network Monitor by Paessler
CVE-2017-15008

4.8MEDIUM

Key Information:

Vendor

Paessler

Vendor
CVE Published:
3 October 2022

What is CVE-2017-15008?

The PRTG Network Monitor version 17.3.33.2830 contains a vulnerability that allows for stored Cross-Site Scripting (XSS) due to faulty error handling in sensor titles. Malicious actors can exploit this issue by injecting harmful scripts through the SRC attribute of an IMG element, specifically when it is incorrectly processed with a %00 byte. This enables an attacker to execute arbitrary scripts in the context of the affected application, posing risks to user data and application integrity.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.