Loading
XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties. An attacker with Read/Write privileges can create a map, and then use the Map Designer Properties screen to insert JavaScript code. This can be exploited against any user with View Maps or Edit Maps access.
Use CWE-79, Paessler vendor hub and Prtg Network Monitor product page to widen CVE-2020-14073 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-31452, CVE-2023-32782 and CVE-2023-32781 for nearby disclosures in the same product family. Additional editorial context is available in Why “Low” and “Medium” CVEs Still Breach Networks.