CVE-2024-4562

MEDIUM

WhatsUp Gold < 23.1.2 - Authenticated Server-Side Request Forgery in HTTP Monitoring

Title source: llm
STIX 2.1

Description

In WhatsUp Gold versions released before 2023.1.2 , an SSRF vulnerability exists in Whatsup Gold's Issue exists in the HTTP Monitoring functionality.  Due to the lack of proper authorization, any authenticated user can access the HTTP monitoring functionality, what leads to the Server Side Request Forgery.

References (2)

Core 2

Scores

CVSS v3 5.4
EPSS 0.0003
EPSS Percentile 9.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
progress/whatsup_gold < 23.1.2
Published May 14, 2024
Tracked Since Feb 18, 2026