PT-2017-13812 · Paessler · Prtg Network Monitor

Published

2017-10-03

·

Updated

2017-10-12

·

CVE-2017-15008

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PRTG Network Monitor version 17.3.33.2830
Description The issue is related to stored Cross-Site Scripting on all sensor titles, due to incorrect error handling for a %00 in the SRC attribute of an IMG element.
Recommendations For version 17.3.33.2830, update to a newer version that addresses the stored Cross-Site Scripting issue to prevent exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-15008

Affected Products

Prtg Network Monitor