First published: Tue Jun 23 2020(Updated: )
XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties. An attacker with Read/Write privileges can create a map, and then use the Map Designer Properties screen to insert JavaScript code. This can be exploited against any user with View Maps or Edit Maps access.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Paessler PRTG Traffic Grapher | =20.1.56.1574 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14073 is a vulnerability that allows for cross-site scripting (XSS) in PRTG Network Monitor version 20.1.56.1574.
The severity of CVE-2020-14073 is medium, with a severity value of 5.4.
CVE-2020-14073 allows an attacker with Read/Write privileges to create a map in PRTG Network Monitor and insert JavaScript code using the Map Designer Properties screen.
Any user with View Maps or Edit Maps access in PRTG Network Monitor can be affected by CVE-2020-14073.
Yes, it is recommended to update to a version of PRTG Network Monitor that is not affected by CVE-2020-14073.