peter bassill · operator
$ cve CVE-2020-14073 JSON

CVE-2020-14073 EXPLOIT

5.4
MEDIUM · CVSS 3.1 · EPSS 2.9% (pctl 86)

Patch early

A public exploit exists.

Description

XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties. An attacker with Read/Write privileges can create a map, and then use the Map Designer Properties screen to insert JavaScript code. This can be exploited against any user with View Maps or Edit Maps access.

Scoring

CVSS5.4 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS2.86% — more likely to be exploited than 86% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2020-06-23
Last modified2026-06-17

Affected (1)

VendorProduct
paesslerprtg network monitor

Public exploits

SourceTitleDate
exploit-dbPRTG Network Monitor 20.4.63.1412 - 'maps' Stored XSS2020-12-02

References

→ the Explorer  ·  watch your stack  ·  NVD