First published: Tue May 14 2024(Updated: )
In WhatsUp Gold versions released before 2023.1.2 , a blind SSRF vulnerability exists in Whatsup Gold's FaviconController that allows an attacker to send arbitrary HTTP requests on behalf of the vulnerable server.
Credit: security@progress.com
Affected Software | Affected Version | How to fix |
---|---|---|
Progress Software WhatsUp Gold | <23.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-4561 is considered a high severity vulnerability due to its potential for blind SSRF exploitation.
To fix CVE-2024-4561, upgrade your WhatsUp Gold version to 2023.1.2 or later.
CVE-2024-4561 affects WhatsUp Gold versions prior to 2023.1.2.
CVE-2024-4561 is a blind Server-Side Request Forgery (SSRF) vulnerability.
CVE-2024-4561 can be exploited by sending arbitrary HTTP requests from the vulnerable server.