Impact
The vulnerability is a reflected cross-site scripting flaw that causes the web interface to display an attacker‑supplied URL path in a 403 error page without proper encoding. When a user with an active PRTG session opens a malicious URL, arbitrary JavaScript runs in the browser as if it came from the authenticated session, giving the attacker the ability to read the session cookie because it is not marked HttpOnly. This results in session hijacking and potential confidentiality breaches.
Affected Systems
Paessler GmbH’s PRTG Network Monitor versions prior to 26.2.120.1449 are affected.
Risk and Exploitability
The CVSS score of 5.1 classifies the weakness as moderate. No EPSS value is reported, and the vulnerability is not in CISA KEV. The attacker must be able to send a crafted URL to a user who is logged into the interface; no privileged access or system exploits are required. If successful, the attacker can steal the session cookie and hijack the account. Because the interface is exposed over the network, the opportunity for exploitation exists for unauthenticated attackers who can prompt victims to visit the malicious link.
OpenCVE Enrichment