PT-2018-1931 · Paessler · Prtg Network Monitor
Dmitry Galecha
·
Published
2018-05-07
·
Updated
2025-03-14
·
CVE-2018-19410
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
PRTG Network Monitor versions prior to 18.2.40.1683
Description
The issue is related to insecure privilege management in PRTG Network Monitor, allowing remote unauthenticated attackers to create users with read-write privileges, including administrators. This can be achieved by crafting an HTTP request to override attributes of the 'include' directive in /public/login.htm, performing a Local File Inclusion attack by including and executing /api/addusers. The attack involves providing the
id and users parameters.Recommendations
For versions prior to 18.2.40.1683, update to version 18.2.40.1683 or later to resolve the issue. As a temporary workaround, consider restricting access to the /public/login.htm and /api/addusers endpoints to minimize the risk of exploitation. Additionally, restrict the use of the
id and users parameters in the affected API endpoint until the issue is resolved.Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prtg Network Monitor