ZDI-CAN-23874: ZDI-24-884: Progress Software WhatsUp Gold LoadCSSUsingBasePath Directory Traversal Information Disclosure Vulnerability
Published Jul 3, 2024
·Updated
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Progress Software WhatsUp Gold. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2024-5019.
Affected Software
1 affected component
Progress Software WhatsUp Gold
Event History
Jul 3, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-23874?
The ZDI-CAN-23874 vulnerability has been assigned a CVSS rating of 5.3.
2
What type of vulnerability is ZDI-CAN-23874?
ZDI-CAN-23874 is a remote information disclosure vulnerability in Progress Software WhatsUp Gold.
3
Does ZDI-CAN-23874 require authentication to exploit?
No, ZDI-CAN-23874 can be exploited without authentication.
4
What software is affected by ZDI-CAN-23874?
ZDI-CAN-23874 affects installations of Progress Software WhatsUp Gold.
5
How can I mitigate the risk of ZDI-CAN-23874?
Mitigation strategies for ZDI-CAN-23874 include applying security patches and restricting access to the affected application.