Bug 2343883 (CVE-2018-19410) - CVE-2018-19410 PRTG Network Monitor: Authentication Bypass, Improper Authorization and Local File Inclusion in PRTG Network Monitor
Summary: CVE-2018-19410 PRTG Network Monitor: Authentication Bypass, Improper Authoriz...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2018-19410
Product: Security Response
Classification: Other
Component: vulnerability-draft
Version: unspecified
Hardware: All
OS: Linux
urgent
urgent
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-02-05 07:48 UTC by OSIDB Bzimport
Modified: 2025-06-25 16:31 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2025-06-25 16:31:59 UTC
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-02-05 07:48:24 UTC
PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user can craft an HTTP request and override attributes of the 'include' directive in /public/login.htm and perform a Local File Inclusion attack, by including /api/addusers and executing it. By providing the 'id' and 'users' parameters, an unauthenticated attacker can create a user with read-write privileges (including administrator).


Note You need to log in before you can comment on or make changes to this bug.