Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-35739

Опубликовано: 25 окт. 2022
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

PRTG Network Monitor through 22.2.77.2204 does not prevent custom input for a device’s icon, which can be modified to insert arbitrary content into the style tag for that device. When the device page loads, the arbitrary Cascading Style Sheets (CSS) data is inserted into the style tag, loading malicious content. Due to PRTG Network Monitor preventing “characters, and from modern browsers disabling JavaScript support in style tags, this vulnerability could not be escalated into a Cross-Site Scripting vulnerability.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:paessler:prtg_network_monitor:*:*:*:*:*:*:*:*
Версия до 22.3.79.2108 (исключая)

EPSS

Процентиль: 78%
0.01166
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 5.3
github
больше 2 лет назад

PRTG Network Monitor through 22.2.77.2204 does not prevent custom input for a device’s icon, which can be modified to insert arbitrary content into the style tag for that device. When the device page loads, the arbitrary Cascading Style Sheets (CSS) data is inserted into the style tag, loading malicious content. Due to PRTG Network Monitor preventing “characters, and from modern browsers disabling JavaScript support in style tags, this vulnerability could not be escalated into a Cross-Site Scripting vulnerability.

EPSS

Процентиль: 78%
0.01166
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-79
CWE-79