HIGH
WhatsUp Gold LoadCSSUsingBasePath Directory Traversal Information Disclosure Vulnerability
Published Jun 25, 2024
7.5
HIGHCVSS 3.1
EPSS 0.77%
Description
In WhatsUp Gold versions released before 2023.1.3,
an unauthenticated Arbitrary File Read issue exists in Wug.UI.Areas.Wug.Controllers.SessionController.CachedCSS. This vulnerability allows reading of any file with iisapppool\NmConsole privileges.
Affected products
-
- Version 2023.1.0StatusaffectedConstraints<2023.1.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Progress Software Corporation | WhatsUp Gold | affected |
|
- < 23.1.3
-
- Version 2023.1.0StatusaffectedConstraints<2023.1.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Progress | Whatsup Gold | affected |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-June-2024 vendor-advisoryVendor Advisory
- https://www.progress.com/network-monitoring product
| Link | Providers | Tags |
|---|---|---|
| https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-June-2024 | vendor-advisoryVendor Advisory | |
| https://www.progress.com/network-monitoring | product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ProgressSoftware
Published Jun 25, 2024
Updated Aug 1, 2024
Reserved May 16, 2024
Link CVE-2024-5019
CISA Vulnrichment
Updated Jun 26, 2024