Showing 3 vulnerabilities on this page for WhatsUp Gold

Signals CISA KEV Ransomware Nuclei
Progress vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WhatsUp Gold GetStatisticalMonitorList SQL Injection Authentication Bypass Vulnerability

In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

CWE-89Aug 29, 20241 related artifact
CVSS9.8v3.1EPSS14.9%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability

In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

CWE-89Aug 29, 20241 related artifact
CVSS9.8v3.1EPSS94.7%PoCs2SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\nmconsole privileges.

CWE-22Jun 25, 20241 related artifact
CVSS9.8v3.1EPSS99.3%PoCs1SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX