Cross-Site Request Forgery Vulnerability in PRTG by Paessler
CVE-2023-31452

8.8HIGH

Key Information:

Vendor

Paessler

Vendor
CVE Published:
9 August 2023

What is CVE-2023-31452?

A cross-site request forgery (CSRF) token bypass vulnerability has been detected in PRTG versions 23.2.84.1566 and earlier. This flaw enables remote attackers to manipulate actions on behalf of authenticated users who have active sessions. By enticing a victim to activate a malicious request, attackers can execute various operations within the PRTG system, potentially leading to the creation of unauthorized users and other critical actions that compromise the application's integrity. Addressing this concern is crucial for maintaining secure network monitoring practices.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.