CVE-2024-5019: WhatsUp Gold LoadCSSUsingBasePath Directory Traversal Information Disclosure Vulnerability
In WhatsUp Gold versions released before 2023.1.3,
an unauthenticated Arbitrary File Read issue exists in Wug.UI.Areas.Wug.Controllers.SessionController.CachedCSS. This vulnerability allows reading of any file with iisapppool\NmConsole privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WhatsUp Goldto a version that resolves this vulnerability.Fixed in 2023.1.3
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5019?
CVE-2024-5019 is classified as a medium severity vulnerability due to its potential for arbitrary file read exploits.
How do I fix CVE-2024-5019?
To fix CVE-2024-5019, upgrade WhatsUp Gold to version 2023.1.3 or later.
What versions of WhatsUp Gold are affected by CVE-2024-5019?
WhatsUp Gold versions prior to 2023.1.3 are affected by CVE-2024-5019.
What type of vulnerability is CVE-2024-5019?
CVE-2024-5019 is an unauthenticated arbitrary file read vulnerability.
What privileges are required to exploit CVE-2024-5019?
Exploitation of CVE-2024-5019 requires access to files with iisapppool\NmConsole privileges.