ZDI-24-890: Progress Software WhatsUp Gold SessionControler Server-Side Request Forgery Information Disclosure Vulnerability
This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Progress Software WhatsUp Gold. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2024-5015.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-890?
The severity of ZDI-24-890 is rated at 7.1 on the CVSS scale, indicating a high risk.
How do I fix ZDI-24-890?
To mitigate ZDI-24-890, ensure that all installations of Progress Software WhatsUp Gold are updated to the latest version provided by the vendor.
What type of attack does ZDI-24-890 allow?
ZDI-24-890 allows remote attackers to initiate arbitrary server-side requests on affected installations.
Is authentication required to exploit ZDI-24-890?
Yes, authentication is required to exploit the ZDI-24-890 vulnerability.
What products are affected by ZDI-24-890?
The affected product for ZDI-24-890 is Progress Software WhatsUp Gold.