Vulnerabilities > Paessler > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-02-08 CVE-2023-51630 Cross-site Scripting vulnerability in Paessler Prtg Network Monitor
Paessler PRTG Network Monitor Cross-Site Scripting Authentication Bypass Vulnerability.
network
low complexity
paessler CWE-79
6.1
2023-08-09 CVE-2023-31448 Path Traversal vulnerability in Paessler Prtg Network Monitor
A path traversal vulnerability was identified in the HL7 sensor in PRTG 23.2.84.1566 and earlier versions where an authenticated user with write permissions could trick the HL7 sensor into behaving differently for existing files and non-existing files.
network
low complexity
paessler CWE-22
4.7
2023-08-09 CVE-2023-31449 Path Traversal vulnerability in Paessler Prtg Network Monitor
A path traversal vulnerability was identified in the WMI Custom sensor in PRTG 23.2.84.1566 and earlier versions where an authenticated user with write permissions could trick the WMI Custom sensor into behaving differently for existing files and non-existing files.
network
low complexity
paessler CWE-22
4.7
2023-08-09 CVE-2023-31450 Path Traversal vulnerability in Paessler Prtg Network Monitor
A path traversal vulnerability was identified in the SQL v2 sensors in PRTG 23.2.84.1566 and earlier versions where an authenticated user with write permissions could trick the SQL v2 sensors into behaving differently for existing files and non-existing files.
network
low complexity
paessler CWE-22
4.7
2022-10-25 CVE-2022-35739 Cross-site Scripting vulnerability in Paessler Prtg Network Monitor
PRTG Network Monitor through 22.2.77.2204 does not prevent custom input for a device’s icon, which can be modified to insert arbitrary content into the style tag for that device.
network
low complexity
paessler CWE-79
5.3
2021-09-13 CVE-2021-29643 Cross-site Scripting vulnerability in Paessler Prtg Network Monitor
PRTG Network Monitor before 21.3.69.1333 allows stored XSS via an unsanitized string imported from a User Object in a connected Active Directory instance.
network
low complexity
paessler CWE-79
5.4
2021-06-10 CVE-2021-34547 Cross-Site Request Forgery (CSRF) vulnerability in Paessler Prtg Network Monitor 20.1.55.1775
PRTG Network Monitor 20.1.55.1775 allows /editsettings CSRF for user account creation.
network
low complexity
paessler CWE-352
4.3
2021-03-31 CVE-2021-27220 Unspecified vulnerability in Paessler Prtg Network Monitor
An issue was discovered in PRTG Network Monitor before 21.1.66.1623.
network
low complexity
paessler
5.3
2020-06-23 CVE-2020-14073 Cross-site Scripting vulnerability in Paessler Prtg Network Monitor 20.1.56.1574
XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties.
network
low complexity
paessler CWE-79
5.4
2020-04-05 CVE-2020-11547 Missing Authentication for Critical Function vulnerability in Paessler Prtg Network Monitor
PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version, and internal statistics) via an HTTP request, as demonstrated by type=probes to login.htm or index.htm.
network
low complexity
paessler CWE-306
5.3