/Vulnerability Library

WhatsUp Gold GetStatisticalMonitorList SQL Injection - Authentication Bypass

CVE-2024-6671
Verified

Description

In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

Severity

Critical

CVSS Score

9.8

Exploit Probability

19%

Affected Product

whatsup_gold

Published Date

September 2, 2024

Template Author

daffainfo, jjcho

CVE-2024-6671.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2024-6671
CWE ID:
cwe-89

References

https://www.zerodayinitiative.com/advisories/ZDI-24-1186/https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-August-2024https://www.progress.com/network-monitoring

Remediation Steps

Update WhatsUp Gold to version 2024.0.0 or later to address the SQL injection vulnerability.