CVE-2024-5015

HIGH

Progress Whatsup Gold < 23.1.3 - SSRF

Title source: rule

Description

In WhatsUp Gold versions released before 2023.1.3, an authenticated SSRF vulnerability in Wug.UI.Areas.Wug.Controllers.SessionControler.Update allows a low privileged user to chain this SSRF with an Improper Access Control vulnerability. This can be used to escalate privileges to Admin.

Scores

CVSS v3 7.1
EPSS 0.0009
EPSS Percentile 25.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Classification

CWE
CWE-918
Status published

Affected Products (1)

progress/whatsup_gold < 23.1.3

Timeline

Published Jun 25, 2024
Tracked Since Feb 18, 2026