CVE-2022-42711: XSS
Published Oct 12, 2022
·Updated
In Progress WhatsUp Gold before 22.1.0, an SNMP MIB Walker application endpoint failed to adequately sanitize malicious input. This could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.
Affected Software
1 affected component
Progress WhatsUp Gold<22.1.0
Event History
Oct 12, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-42711?
CVE-2022-42711 is a vulnerability in the SNMP MIB Walker application endpoint in WhatsUp Gold before version 22.1.0.
2
How does CVE-2022-42711 impact WhatsUp Gold?
CVE-2022-42711 can allow an unauthenticated attacker to execute arbitrary code in a victim's browser.
3
What is the severity of CVE-2022-42711?
The severity of CVE-2022-42711 is critical with a CVSS score of 9.6.
4
What software versions are affected by CVE-2022-42711?
WhatsUp Gold versions before 22.1.0 are affected by CVE-2022-42711.
5
How can I fix CVE-2022-42711 in WhatsUp Gold?
To fix CVE-2022-42711, update your WhatsUp Gold software to version 22.1.0 or later.