Junglewise Threat Intelligence

CVE-2023-28148: Paessler PRTG cross-site scripting in body class

CVE-2023-28148 · Severity: high · CVSS 7.2 · Published 2026-09-14

Technologies: Paessler PRTG Network Monitor. Vendors: Paessler.

Executive brief

Paessler PRTG is a network monitoring tool used by IT teams to track system health and performance. A stored cross-site scripting (XSS) vulnerability in the body class attribute allows attackers to inject malicious code that executes in users' browsers, potentially leading to credential theft, session hijacking, or unauthorized actions on monitored systems.

Technical details

A stored XSS vulnerability exists in Paessler PRTG versions before 23.3.86.1520 within the body class attribute. The vulnerability stems from insufficient input validation or output encoding of user-supplied data that is rendered in the HTML body element's class attribute. An attacker can inject arbitrary HTML and JavaScript by crafting a malicious payload; the attack requires prior authentication or access to an input field that populates the body class. Successful exploitation allows the attacker's JavaScript to execute in the context of other users' sessions, enabling session hijacking, credential theft, or modification of monitoring configurations. The vulnerability was patched in version 23.3.86.1520 and later.

Affected products

  • Paessler PRTG Network Monitor before 23.3.86.1520

Timeline

  • 2023-09-14: disclosed

References

Related threats