CVE-2023-28148
largeUnauthenticated XSS via bodyclass Parameter in Paessler PRTG Network Monitor
CVE-2023-28148 is a cross-site scripting (CWE-79) flaw in the web interface of Paessler PRTG Network Monitor in versions before 23.3.86.1520, involving improper handling of the 'bodyclass' parameter. An unauthenticated remote attacker can inject malicious script content through a crafted request to the PRTG web console; the supplied CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:C) rates this as high severity with no privileges or user interaction required. If executed in the browser of a logged-in PRTG administrator, the injected script could allow session theft or unauthorized actions against the monitored infrastructure via the monitoring console. Any organization running an unpatched on-premises PRTG server is affected, with risk concentrated where the web interface is reachable by untrusted users or exposed to the internet. No public proof of concept is known, the flaw is not on the CISA KEV list, and there are no reports of exploitation in the wild.
What to do: Upgrade PRTG Network Monitor to version 23.3.86.1520 or later (any current 23.4.x+ release contains the fix). Restrict the PRTG web administration console to trusted internal networks or VPN access and remove any internet-facing exposure. Review web server logs for anomalous requests containing unexpected bodyclass parameters and audit administrative accounts and sessions for signs of abuse.
| Paessler PRTG Network Monitor | < 23.3.86.1520 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.