CVE-2023-6595

HIGH

WhatsUp Gold <2023.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate ancillary credential information stored within WhatsUp Gold.

Exploits (1)

nomisec STUB
by sharmashreejaa · poc
https://github.com/sharmashreejaa/CVE-2023-6595

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0033
EPSS Percentile 56.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-306
Status published
Products (1)
progress/whatsup_gold < 23.1.0
Published Dec 14, 2023
Tracked Since Feb 18, 2026