CVE-2024-46905: WhatsUp Gold GetOrderByClause SQL Injection Privilege Escalation Vulnerability
Published Dec 2, 2024
·Updated
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated lower-privileged user (at least Network Manager permissions required) to achieve privilege escalation to the admin account.
Affected Software
1 affected component
Progress WhatsUp Gold<24.0.1
Event History
Dec 2, 2024
CVE Published
via MITRE·02:45 PM
Data Sourced
via MITRE·02:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-46905?
CVE-2024-46905 is classified as a high severity vulnerability due to its potential for privilege escalation.
2
Who is affected by CVE-2024-46905?
CVE-2024-46905 affects authenticated users with Network Manager permissions on WhatsUp Gold versions prior to 2024.0.1.
3
How do I fix CVE-2024-46905?
To fix CVE-2024-46905, upgrade to WhatsUp Gold version 2024.0.1 or later.
4
What type of vulnerability is CVE-2024-46905?
CVE-2024-46905 is a SQL Injection vulnerability that allows for privilege escalation.
5
What privileges are required to exploit CVE-2024-46905?
Exploiting CVE-2024-46905 requires at least Network Manager permissions.