First published: Tue Jun 25 2024(Updated: )
In WhatsUp Gold versions released before 2023.1.3, an authenticated user with certain permissions can upload an arbitrary file and obtain RCE using Apm.UI.Areas.APM.Controllers.Api.Applications.AppProfileImportController.
Credit: security@progress.com
Affected Software | Affected Version | How to fix |
---|---|---|
Progress Software WhatsUp Gold | <23.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5008 has a high severity rating due to the potential for remote code execution.
To fix CVE-2024-5008, upgrade WhatsUp Gold to version 23.1.3 or later.
CVE-2024-5008 affects authenticated users in WhatsUp Gold versions earlier than 23.1.3.
CVE-2024-5008 is a file upload vulnerability that can lead to remote code execution.
There are no known workarounds for CVE-2024-5008 other than applying the security update.