First published: Tue Jun 25 2024(Updated: )
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Arbitrary File Read issue exists in Wug.UI.Areas.Wug.Controllers.SessionController.CachedCSS. This vulnerability allows reading of any file with iisapppool\NmConsole privileges.
Credit: security@progress.com
Affected Software | Affected Version | How to fix |
---|---|---|
Progress Software WhatsUp Gold | <23.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5019 is classified as a medium severity vulnerability due to its potential for arbitrary file read exploits.
To fix CVE-2024-5019, upgrade WhatsUp Gold to version 2023.1.3 or later.
WhatsUp Gold versions prior to 2023.1.3 are affected by CVE-2024-5019.
CVE-2024-5019 is an unauthenticated arbitrary file read vulnerability.
Exploitation of CVE-2024-5019 requires access to files with iisapppool\NmConsole privileges.