ZDI-CAN-23667: ZDI-24-1187: Progress Software WhatsUp Gold getMonitorJoin SQL Injection Privilege Escalation Vulnerability
This vulnerability allows remote attackers to escalate privileges on affected installations of Progress Software WhatsUp Gold. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-6672.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23667?
ZDI-CAN-23667 has a significant severity level due to its ability to allow remote privilege escalation.
How do I fix ZDI-CAN-23667?
To fix ZDI-CAN-23667, apply the latest security patches provided by Progress Software for WhatsUp Gold.
What software is affected by ZDI-CAN-23667?
ZDI-CAN-23667 affects installations of Progress Software WhatsUp Gold.
Can ZDI-CAN-23667 be exploited without authentication?
While ZDI-CAN-23667 requires authentication, the existing authentication mechanism can be bypassed, making it more vulnerable.
What kind of vulnerability is ZDI-CAN-23667?
ZDI-CAN-23667 is a remote privilege escalation vulnerability.