Cross-Site Scripting Vulnerability in Paessler PRTG Network Monitor
CVE-2023-28148

7.2HIGH

Key Information:

Vendor

Paessler

Vendor
CVE Published:
14 September 2026

What is CVE-2023-28148?

A cross-site scripting (XSS) vulnerability exists in Paessler PRTG Network Monitor, specifically in versions prior to 23.3.86.1520. This flaw can be exploited by an attacker to inject malicious scripts into web pages viewed by users, potentially compromising user sessions and sensitive data. It is crucial for users to update their installations to mitigate this security risk. For more information and updates, refer to the official Paessler history page.

Affected Version(s)

PRTG Network Monitor 0 < 23.3.86.1520

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.