ZDI-CAN-23447: ZDI-24-516: Progress Software WhatsUp Gold HttpContentActiveController Server-Side Request Forgery Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Progress Software WhatsUp Gold. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2024-4562.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23447?
The ZDI-CAN-23447 vulnerability has a CVSS rating of 7.1, indicating it is of high severity.
How do I fix ZDI-CAN-23447?
To fix ZDI-CAN-23447, apply the latest security patch or update for Progress Software WhatsUp Gold as recommended by the vendor.
What kind of attacks can exploit ZDI-CAN-23447?
ZDI-CAN-23447 allows remote attackers to disclose sensitive information if they have valid authentication credentials.
Is authentication required to exploit ZDI-CAN-23447?
Yes, authentication is required to exploit the ZDI-CAN-23447 vulnerability.
What software is affected by ZDI-CAN-23447?
ZDI-CAN-23447 affects installations of Progress Software WhatsUp Gold.