Executive brief
Paessler PRTG Network Monitor contains a local file inclusion (LFI) vulnerability in the 'include' directive of /public/login.htm. A remote, unauthenticated attacker can exploit this by including /api/addusers to create new user accounts with read-write or administrator privileges.
Affected products
- Paessler PRTG Network Monitor before 18.2.40.1683
Timeline
- 2018-11-21: disclosed: NVD Published Date
- 2025-02-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog