{"id":"CVE-2018-19410","aliases":[],"url":"https://o3.security/vulnerability/CVE-2018-19410","summary":"PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user…","details":"PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user can craft an HTTP request and override attributes of the 'include' directive in /public/login.htm and perform a Local File Inclusion attack, by including /api/addusers and executing it. By providing the 'id' and 'users' parameters, an unauthenticated attacker can create a user with read-write privileges (including administrator).","published":"2018-11-21T16:29:00.347","modified":"2026-06-17T01:49:15.640","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.97939,"percentile":0.99906,"asOf":"2026-08-28"},"cisaKev":{"dateAdded":"2025-02-04","dueDate":"2025-02-25","knownRansomwareCampaignUse":false},"exploitsKnown":1,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"https://www.ptsecurity.com/ww-en/analytics/threatscape/pt-2018-24/"},{"type":"ADVISORY","url":"https://www.ptsecurity.com/ww-en/analytics/threatscape/pt-2018-24/"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19410"}],"provenance":{"sources":["OSV.dev","NVD","CISA KEV","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T01:49:15.640"}}