Cross-Site Scripting Vulnerability in PRTG Network Monitor by Paessler
CVE-2020-14073

5.4MEDIUM

Key Information:

Vendor

Paessler

Vendor
CVE Published:
23 June 2020

What is CVE-2020-14073?

A Cross-Site Scripting (XSS) vulnerability exists in PRTG Network Monitor version 20.1.56.1574. The flaw allows an authenticated attacker with Read/Write privileges to create a malicious map using the Map Designer Properties screen. By injecting JavaScript code into the map properties, the attacker can execute scripts in the context of any user who views or edits the map. This poses a significant risk to users, as the malicious scripts can lead to unauthorized actions and data exposure, highlighting the importance of securing access to mapping functionalities.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.