Vulnerability Description
PRTG Network Monitor before 18.2.40.1683 allows an authenticated user with a read-only account to create another user with a read-write account (including administrator) via an HTTP request because /api/addusers doesn't check, or doesn't properly check, user rights.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Paessler | Prtg Network Monitor | < 18.2.40.1683 |
Related Weaknesses (CWE)
References
- https://www.ptsecurity.com/ww-en/analytics/threatscape/pt-2018-25/Third Party Advisory
- https://www.ptsecurity.com/ww-en/analytics/threatscape/pt-2018-25/Third Party Advisory
FAQ
What is CVE-2018-19411?
CVE-2018-19411 is a vulnerability with a CVSS score of 8.8 (HIGH). PRTG Network Monitor before 18.2.40.1683 allows an authenticated user with a read-only account to create another user with a read-write account (including administrator) via an HTTP request because /a...
How severe is CVE-2018-19411?
CVE-2018-19411 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-19411?
Check the references section above for vendor advisories and patch information. Affected products include: Paessler Prtg Network Monitor.