ZeroHour

CVE-2023-28148

large

Unauthenticated XSS via bodyclass Parameter in Paessler PRTG Network Monitor

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

CVE-2023-28148 is a cross-site scripting (CWE-79) flaw in the web interface of Paessler PRTG Network Monitor in versions before 23.3.86.1520, involving improper handling of the 'bodyclass' parameter. An unauthenticated remote attacker can inject malicious script content through a crafted request to the PRTG web console; the supplied CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:C) rates this as high severity with no privileges or user interaction required. If executed in the browser of a logged-in PRTG administrator, the injected script could allow session theft or unauthorized actions against the monitored infrastructure via the monitoring console. Any organization running an unpatched on-premises PRTG server is affected, with risk concentrated where the web interface is reachable by untrusted users or exposed to the internet. No public proof of concept is known, the flaw is not on the CISA KEV list, and there are no reports of exploitation in the wild.

What to do: Upgrade PRTG Network Monitor to version 23.3.86.1520 or later (any current 23.4.x+ release contains the fix). Restrict the PRTG web administration console to trusted internal networks or VPN access and remove any internet-facing exposure. Review web server logs for anomalous requests containing unexpected bodyclass parameters and audit administrative accounts and sessions for signs of abuse.

Affected
Paessler PRTG Network Monitor< 23.3.86.1520
Estimated exposure
large≈300,000 users across tens of thousands of on-premises deployments, of which only a few thousand web consoles appear internet-exposed — Paessler markets PRTG to hundreds of thousands of IT users worldwide, while public internet scans (e.g., Shodan/Censys) typically show only a few thousand PRTG web interfaces (commonly port 8080) reachable from the internet, since most…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.

Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.