CVE-2024-5015
HIGHProgress Whatsup Gold < 23.1.3 - SSRF
Title source: ruleDescription
In WhatsUp Gold versions released before 2023.1.3, an authenticated SSRF vulnerability in Wug.UI.Areas.Wug.Controllers.SessionControler.Update allows a low privileged user to chain this SSRF with an Improper Access Control vulnerability. This can be used to escalate privileges to Admin.
Scores
CVSS v3
7.1
EPSS
0.0009
EPSS Percentile
25.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Classification
CWE
CWE-918
Status
published
Affected Products (1)
progress/whatsup_gold
< 23.1.3
Timeline
Published
Jun 25, 2024
Tracked Since
Feb 18, 2026