First published: Fri Jun 23 2023(Updated: )
In Progress WhatsUp Gold before 23.0.0, an SNMP-related application endpoint failed to adequately sanitize malicious input. This could allow an unauthenticated attacker to execute arbitrary code in a victim's browser, aka XSS.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Progress WhatsUp Gold | <23.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-35759.
Progress WhatsUp Gold before version 23.0.0 is affected by CVE-2023-35759.
CVE-2023-35759 has a severity value of 6.1, which is considered medium.
CVE-2023-35759 falls under the CWE category 79, which is Cross-Site Scripting (XSS).
An unauthenticated attacker can exploit CVE-2023-35759 by executing arbitrary code in a victim's browser through a malicious input in an SNMP-related application endpoint.