CVE-2024-5009
HIGHProgress Whatsup Gold < 23.1.3 - Improper Privilege Management
Title source: ruleDescription
In WhatsUp Gold versions released before 2023.1.3, an Improper Access Control vulnerability in Wug.UI.Controllers.InstallController.SetAdminPassword allows local attackers to modify admin's password.
Exploits (2)
Scores
CVSS v3
8.4
EPSS
0.3601
EPSS Percentile
97.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-269
Status
published
Products (1)
progress/whatsup_gold
< 23.1.3
Published
Jun 25, 2024
Tracked Since
Feb 18, 2026