Description
A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.
Published: 2026-09-14
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

A browser principal body class input field in Paessler can inject arbitrary script code into web pages served by the application. The injected script executes in the context of the victim’s browser, allowing session hijacking, cookie theft, or defacement of the monitored interface. This weakness is classified as CWE‑79 and is normally triggered when an unauthenticated user supplies malicious input that is reflected within the body class attribute of an HTML page.

Affected Systems

The vulnerability affects all installations of Paessler PRTG Network Monitor running versions prior to 23.3.86.1520, regardless of deployment size or geographical location. The affected component is the body class handling in the web UI, which is exposed to end‑user input on any accessible instance of the monitoring system.

Risk and Exploitability

The CVSS base score of 7.2 indicates a high risk of exploitation if an attacker can reach the susceptible input. The EPSS score of < 1 in the general population, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is a web‑based request containing a malicious body class, which can be crafted by an attacker who can direct traffic to the application or by an insider with access to the web interface. Because the vulnerability does not require elevated privileges, any authenticated or unauthenticated user could abuse it if they can submit payloads to the site.

Generated by OpenCVE AI on September 15, 2026 at 16:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PRTG to version 23.3.86.1520 or later, which removes the body class injection point
  • Configure a content security policy that restricts inline scripts and disallows the execution of unknown JavaScript
  • Review and sanitize all user‑supplied input that populates HTML attributes to ensure it cannot contain executable code

Generated by OpenCVE AI on September 15, 2026 at 16:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title Body Class Injection XSS in Paessler PRTG Network Monitor

Mon, 14 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Body Class XSS Vulnerability in Paessler PRTG Network Monitor

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Title Body Class XSS Vulnerability in Paessler PRTG Network Monitor

Mon, 14 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Description A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.
First Time appeared Paessler
Paessler prtg Network Monitor
Weaknesses CWE-79
CPEs cpe:2.3:a:paessler:prtg_network_monitor:*:*:*:*:*:*:*:*
Vendors & Products Paessler
Paessler prtg Network Monitor
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Paessler Prtg Network Monitor
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T16:20:44.612Z

Reserved: 2023-03-12T00:00:00.000Z

Link: CVE-2023-28148

cve-icon Vulnrichment

Updated: 2026-09-14T16:20:22.936Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T05:16:56.837

Modified: 2026-09-22T19:56:19.073

Link: CVE-2023-28148

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:15:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')