Stored Cross-Site Scripting Vulnerability in PRTG Network Monitor by Paessler AG
CVE-2017-15360

5.4MEDIUM

Key Information:

Vendor

Paessler

Vendor
CVE Published:
3 October 2022

What is CVE-2017-15360?

PRTG Network Monitor version 17.3.33.2830 is susceptible to a stored Cross-Site Scripting vulnerability due to improper error handling for HTML encoded scripts in group names. This oversight allows an attacker to inject malicious scripts, which can lead to unauthorized access and data theft when unsuspecting users interact with the affected elements.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.