← Vulnerability feed

Vulnerability record · CVE-2024-12833 · published 11 February 2025

CVE-2024-12833: Paessler prtg network monitor cross-site scripting vulnerability

Paessler · Prtg Network Monitor

Paessler PRTG Network Monitor SNMP Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Paessler PRTG Network Monitor. Some user interaction on the part of an administrator is required to exploit this vulnerability. The specific flaw exists within the PRTG Network Monitor web interface. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-23371.

6.1 CVSS 3.1 Medium EPSS 0.86% · top 42.8% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
0.86%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Paessler PRTG Network Monitor SNMP Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Paessler PRTG Network Monitor. Some user interaction on the part of an administrator is required to exploit this vulnerability. The specific flaw exists within the PRTG Network Monitor web interface. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-23371.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-12833 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-19410PRTG Network Monitor unauthenticated local file inclusion enables admin user creationPRTG Network Monitor before 18.2.40.1683 lets an unauthenticated remote attacker abuse the 'include' directive in /public/login.htm to perform local …KEVEPSS 98%analysed7.2CVE-2018-9276PRTG Network Monitor OS Command Injection via Malformed ParametersPRTG Network Monitor before 18.2.39 contains an OS command injection flaw (CWE-78) reachable through malformed parameters in sensor or notification m…KEVEPSS 87%analysed9.8CVE-2020-10374Paessler prtg network monitor improper input validation vulnerabilityA webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST req…EPSS 4.7%8.8CVE-2023-31452Paessler prtg network monitor cross-site request forgery vulnerabilityA cross-site request forgery (CSRF) token bypass was identified in PRTG 23.2.84.1566 and earlier versions that allows remote attackers to perform act…EPSS 0.65%8.8CVE-2018-19411Paessler prtg network monitor improper privilege management vulnerabilityPRTG Network Monitor before 18.2.40.1683 allows an authenticated user with a read-only account to create another user with a read-write account (incl…EPSS 0.87%8.8CVE-2018-19204Paessler prtg network monitor improper input validation vulnerabilityPRTG Network Monitor before 18.3.44.2054 allows a remote authenticated attacker (with read-write privileges) to execute arbitrary code and OS command…EPSS 4.6%7.5CVE-2018-19203Paessler prtg network monitor vulnerabilityPRTG Network Monitor before 18.2.41.1652 allows remote unauthenticated attackers to terminate the PRTG Core Server Service via a special HTTP request.EPSS 2.8%7.5CVE-2018-10253Paessler prtg network monitor memory buffer overflow vulnerabilityPaessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.EPSS 7.2%

Source: NIST National Vulnerability Database (record CVE-2024-12833), CISA KEV, FIRST EPSS (scores of 2026-10-06). This page is refreshed as NVD updates the record.