CVE-2024-5018: WhatsUp Gold LoadUsingBasePath Directory Traversal Information Disclosure Vulnerability
Published Jun 25, 2024
·Updated
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Path Traversal vulnerability exists Wug.UI.Areas.Wug.Controllers.SessionController.LoadNMScript. This allows allows reading of any file from the applications web-root directory .
Affected Software
1 affected component
Progress WhatsUp Gold<23.1.3
Event History
Jun 25, 2024
CVE Published
via MITRE·08:27 PM
Data Sourced
via MITRE·08:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-5018?
CVE-2024-5018 is classified as a critical vulnerability due to its potential for unauthorized file access.
2
How do I fix CVE-2024-5018?
To fix CVE-2024-5018, upgrade to WhatsUp Gold version 2023.1.3 or later.
3
What does CVE-2024-5018 allow attackers to do?
CVE-2024-5018 allows attackers to perform a Path Traversal attack to read any file from the application's web-root directory.
4
Which versions of WhatsUp Gold are affected by CVE-2024-5018?
CVE-2024-5018 affects all versions of WhatsUp Gold prior to 2023.1.3.
5
Is authentication required to exploit CVE-2024-5018?
No, CVE-2024-5018 can be exploited without authentication.