CVE-2024-12833

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
11/02/2025
Last modified:
18/02/2025

Description

Paessler PRTG Network Monitor SNMP Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Paessler PRTG Network Monitor. Some user interaction on the part of an administrator is required to exploit this vulnerability.<br /> <br /> The specific flaw exists within the PRTG Network Monitor web interface. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-23371.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:paessler:prtg_network_monitor:*:*:*:*:*:*:*:* 25.1.102.1373 (excluding)


References to Advisories, Solutions, and Tools