CVE-2018-19410
CVE-2018-19410
In short
PRTG Network Monitor allows anyone on the internet to create administrator accounts without logging in. An attacker can send a specially crafted request to add new users with full control over the system.
Technical detail
A Local File Inclusion (LFI) vulnerability in /public/login.htm permits unauthenticated attackers to include and execute /api/addusers by manipulating the 'include' directive. By supplying 'id' and 'users' parameters in a crafted HTTP request, attackers can create privileged accounts including administrators without authentication.
Summary generated and translated by AI from the official description.
PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user can craft an HTTP request and override attributes of the 'include' directive in /public/login.htm and perform a Local File Inclusion attack, by including /api/addusers and executing it. By providing the 'id' and 'users' parameters, an unauthenticated attacker can create a user with read-write privileges (including administrator).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/apublic PoCs found — 1
githubgithub.com/himash/CVE-2018-19410-POC★ 3⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →