ZDI-CAN-23670: ZDI-24-890: Progress Software WhatsUp Gold SessionControler Server-Side Request Forgery Information Disclosure Vulnerability
This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Progress Software WhatsUp Gold. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2024-5015.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23670?
ZDI-CAN-23670 has a CVSS rating of 7.1, indicating a high severity vulnerability.
What software is affected by ZDI-CAN-23670?
ZDI-CAN-23670 affects installations of Progress Software WhatsUp Gold.
What type of attack does ZDI-CAN-23670 enable?
ZDI-CAN-23670 allows remote attackers to initiate arbitrary server-side requests.
Is authentication required to exploit ZDI-CAN-23670?
Yes, authentication is required to exploit the vulnerability identified as ZDI-CAN-23670.
How can I mitigate the risks associated with ZDI-CAN-23670?
To mitigate risks associated with ZDI-CAN-23670, ensure that your Progress Software WhatsUp Gold is updated to the latest security patch.