ZDI-CAN-24638: ZDI-24-1684: Progress Software WhatsUp Gold GetSqlWhereClause SQL Injection Privilege Escalation Vulnerability
This vulnerability allows remote attackers to escalate privileges on affected installations of Progress Software WhatsUp Gold. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-46906.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-24638?
The vulnerability ZDI-CAN-24638 has a CVSS rating of 8.8, indicating a high severity.
How do I fix ZDI-CAN-24638?
To fix vulnerability ZDI-CAN-24638, update Progress Software WhatsUp Gold to the latest patched version provided by the vendor.
What is the impact of ZDI-CAN-24638?
The impact of ZDI-CAN-24638 allows remote attackers to escalate privileges within the affected installations of WhatsUp Gold.
Is authentication required to exploit ZDI-CAN-24638?
Yes, authentication is required to exploit the ZDI-CAN-24638 vulnerability.
What software is affected by ZDI-CAN-24638?
The affected software for ZDI-CAN-24638 is Progress Software WhatsUp Gold.