First published: Wed Jul 03 2024(Updated: )
This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Progress Software WhatsUp Gold. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2024-5015.
Affected Software | Affected Version | How to fix |
---|---|---|
WhatsUp Gold |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-24-890 is rated at 7.1 on the CVSS scale, indicating a high risk.
To mitigate ZDI-24-890, ensure that all installations of Progress Software WhatsUp Gold are updated to the latest version provided by the vendor.
ZDI-24-890 allows remote attackers to initiate arbitrary server-side requests on affected installations.
Yes, authentication is required to exploit the ZDI-24-890 vulnerability.
The affected product for ZDI-24-890 is Progress Software WhatsUp Gold.