First published: Tue Oct 03 2017(Updated: )
PRTG Network Monitor version 17.3.33.2830 is vulnerable to stored Cross-Site Scripting on all sensor titles, related to incorrect error handling for a %00 in the SRC attribute of an IMG element.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Paessler PRTG Traffic Grapher | =17.3.33.2830 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15008 is rated as a medium severity vulnerability due to its potential to allow stored Cross-Site Scripting attacks.
To fix CVE-2017-15008, upgrade PRTG Network Monitor to a version later than 17.3.33.2830 that addresses this vulnerability.
CVE-2017-15008 is a stored Cross-Site Scripting (XSS) vulnerability affecting PRTG Network Monitor.
CVE-2017-15008 affects PRTG Network Monitor version 17.3.33.2830 specifically.
Yes, CVE-2017-15008 can be exploited remotely by an attacker through the web interface of the affected software.