CVE-2020-14073: XSS
XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties. An attacker with Read/Write privileges can create a map, and then use the Map Designer Properties screen to insert JavaScript code. This can be exploited against any user with View Maps or Edit Maps access.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-14073?
CVE-2020-14073 is a vulnerability that allows for cross-site scripting (XSS) in PRTG Network Monitor version 20.1.56.1574.
What is the severity of CVE-2020-14073?
The severity of CVE-2020-14073 is medium, with a severity value of 5.4.
How does CVE-2020-14073 work?
CVE-2020-14073 allows an attacker with Read/Write privileges to create a map in PRTG Network Monitor and insert JavaScript code using the Map Designer Properties screen.
Who can be affected by CVE-2020-14073?
Any user with View Maps or Edit Maps access in PRTG Network Monitor can be affected by CVE-2020-14073.
Is there a fix for CVE-2020-14073?
Yes, it is recommended to update to a version of PRTG Network Monitor that is not affected by CVE-2020-14073.