Impact
A browser principal body class input field in Paessler can inject arbitrary script code into web pages served by the application. The injected script executes in the context of the victim’s browser, allowing session hijacking, cookie theft, or defacement of the monitored interface. This weakness is classified as CWE‑79 and is normally triggered when an unauthenticated user supplies malicious input that is reflected within the body class attribute of an HTML page.
Affected Systems
The vulnerability affects all installations of Paessler PRTG Network Monitor running versions prior to 23.3.86.1520, regardless of deployment size or geographical location. The affected component is the body class handling in the web UI, which is exposed to end‑user input on any accessible instance of the monitoring system.
Risk and Exploitability
The CVSS base score of 7.2 indicates a high risk of exploitation if an attacker can reach the susceptible input. The EPSS score of < 1 in the general population, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is a web‑based request containing a malicious body class, which can be crafted by an attacker who can direct traffic to the application or by an insider with access to the web interface. Because the vulnerability does not require elevated privileges, any authenticated or unauthenticated user could abuse it if they can submit payloads to the site.
OpenCVE Enrichment