Cross-Site Scripting Authentication Bypass Vulnerability Affects Paessler PRTG Network Monitor
CVE-2023-51630

8.8HIGH

Key Information:

Vendor

Paessler

Vendor
CVE Published:
8 February 2024

What is CVE-2023-51630?

A vulnerability in Paessler PRTG Network Monitor permits remote attackers to bypass authentication through cross-site scripting (XSS). The issue stems from inadequate validation of user-provided data within the web console. This flaw allows attackers to inject arbitrary scripts, necessitating user interaction where the target must be tricked into visiting a malicious webpage or opening a malicious file. Successful exploitation can lead to unauthorized access and control over affected systems.

Affected Version(s)

PRTG Network Monitor 23.2.84.1566

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

CVSS V3.0

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.