ZDI-24-1186: Progress Software WhatsUp Gold GetStatisticalMonitorList SQL Injection Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of Progress Software WhatsUp Gold. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2024-6671.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1186?
The severity of ZDI-24-1186 is rated 9.8 on the CVSS scale, indicating a critical vulnerability.
How do I fix ZDI-24-1186?
To fix ZDI-24-1186, apply the latest security patches released by Progress Software for WhatsUp Gold.
Who is affected by the ZDI-24-1186 vulnerability?
The ZDI-24-1186 vulnerability affects installations of Progress Software WhatsUp Gold.
What type of attack can exploit ZDI-24-1186?
ZDI-24-1186 allows remote attackers to bypass authentication without requiring any credentials.
What is the impact of ZDI-24-1186?
The impact of ZDI-24-1186 is that unauthorized users can gain access to sensitive features of WhatsUp Gold.