CVE-2024-6672: WhatsUp Gold getMonitorJoin SQL Injection Privilege Escalation Vulnerability
Published Aug 29, 2024
·Updated
In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an authenticated low-privileged attacker to achieve privilege escalation by modifying a privileged user's password.
Affected Software
1 affected component
Progress WhatsUp Gold<24.0
Event History
Aug 29, 2024
CVE Published
via MITRE·10:07 PM
Data Sourced
via MITRE·10:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-6672?
CVE-2024-6672 is considered a critical severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2024-6672?
To fix CVE-2024-6672, upgrade WhatsUp Gold to version 2024.0.0 or later.
3
Who is affected by CVE-2024-6672?
CVE-2024-6672 affects all versions of WhatsUp Gold prior to 2024.0.0.
4
What type of vulnerability is CVE-2024-6672?
CVE-2024-6672 is classified as a SQL Injection vulnerability.
5
Can CVE-2024-6672 be exploited remotely?
CVE-2024-6672 requires authentication, meaning it cannot be exploited remotely by an unauthenticated user.