CVE-2018-19410 - Paessler PRTG Network Monitor
AI Vulnerability ContextPRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user can craft an HTTP request and override attributes of the 'include' directive in /public/login.htm and perform a Local File Inclusion attack, by including /api/addusers and executing it. By providing the 'id' and 'users' parameters, an u...
Overview
A source-backed snapshot of this vulnerability.
PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user can craft an HTTP request and override attributes of the 'include' directive in /public/login.htm and perform a Local File Inclusion attack, by including /api/addusers and executing it. By providing the 'id' and 'users' parameters, an unauthenticated attacker can create a user with read-write privileges (including administrator).
Vulnerability status
How serious this vulnerability is and whether it is known to be exploited.
- CVE ID
- CVE-2018-19410
- Vendor/project
- Paessler
- Product
- PRTG Network Monitor
- Vulnerability name
- Paessler PRTG Network Monitor Local File Inclusion Vulnerability
- Date added
- 2025-02-04
- Due date
- 2025-02-25
- Known ransomware campaign use
- Unknown
- CVSS v3
- 9.8
Exploit context
What the vulnerability is about.
PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user can craft an HTTP request and override attributes of the 'include' directive in /public/login.htm and perform a Local File Inclusion attack, by including /api/addusers and executing it. By providing the 'id' and 'users' parameters, an unauthenticated attacker can create a user with read-write privileges (including administrator).
Source evidence
Original public records and references for this page.
Original source
Original source links
Open the public records and source datasets used for this page.
