CVE-2017-15008: XSS
Published Oct 3, 2017
·Updated
PRTG Network Monitor version 17.3.33.2830 is vulnerable to stored Cross-Site Scripting on all sensor titles, related to incorrect error handling for a %00 in the SRC attribute of an IMG element.
Affected Software
1 affected component
Paessler PRTG Network Monitor=17.3.33.2830
Event History
Oct 3, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15008?
CVE-2017-15008 is rated as a medium severity vulnerability due to its potential to allow stored Cross-Site Scripting attacks.
2
How do I fix CVE-2017-15008?
To fix CVE-2017-15008, upgrade PRTG Network Monitor to a version later than 17.3.33.2830 that addresses this vulnerability.
3
What type of vulnerability is CVE-2017-15008?
CVE-2017-15008 is a stored Cross-Site Scripting (XSS) vulnerability affecting PRTG Network Monitor.
4
What versions of PRTG Network Monitor are affected by CVE-2017-15008?
CVE-2017-15008 affects PRTG Network Monitor version 17.3.33.2830 specifically.
5
Can CVE-2017-15008 be exploited remotely?
Yes, CVE-2017-15008 can be exploited remotely by an attacker through the web interface of the affected software.