cve/2022/CVE-2022-35739.md
2024-06-18 02:51:15 +02:00

19 lines
1.0 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

### [CVE-2022-35739](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-35739)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
PRTG Network Monitor through 22.2.77.2204 does not prevent custom input for a devices icon, which can be modified to insert arbitrary content into the style tag for that device. When the device page loads, the arbitrary Cascading Style Sheets (CSS) data is inserted into the style tag, loading malicious content. Due to PRTG Network Monitor preventing “characters, and from modern browsers disabling JavaScript support in style tags, this vulnerability could not be escalated into a Cross-Site Scripting vulnerability.
### POC
#### Reference
- https://raxis.com/blog/cve-2022-35739
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/k0pak4/k0pak4