CVE-2024-46906: WhatsUp Gold GetSqlWhereClause SQL Injection Privilege Escalation Vulnerability
Published Dec 2, 2024
·Updated
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.
Affected Software
1 affected component
Progress WhatsUp Gold<24.0.1
Event History
Dec 2, 2024
CVE Published
via MITRE·02:44 PM
Data Sourced
via MITRE·02:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-46906?
CVE-2024-46906 is classified as a high severity SQL Injection vulnerability that allows for privilege escalation.
2
How do I fix CVE-2024-46906?
To fix CVE-2024-46906, upgrade to WhatsUp Gold version 24.0.1 or later.
3
Who is affected by CVE-2024-46906?
CVE-2024-46906 affects authenticated users with at least Report Viewer permissions in WhatsUp Gold versions prior to 24.0.1.
4
What type of vulnerability is CVE-2024-46906?
CVE-2024-46906 is a SQL Injection vulnerability that can be exploited for privilege escalation.
5
Can CVE-2024-46906 be exploited remotely?
CVE-2024-46906 can only be exploited by authenticated low-privileged users within the affected system.