CVE-2024-6670

CRITICAL KEV RANSOMWARE NUCLEI

WhatsUp Gold SQL Injection (CVE-2024-6670)

Title source: metasploit

Description

In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

Exploits (2)

nomisec WORKING POC 35 stars
by sinsinology · remote
https://github.com/sinsinology/CVE-2024-6670
metasploit WORKING POC
by Michael Heinzl, Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam) · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/whatsup_gold_sqli.rb

Nuclei Templates (1)

WhatsUp Gold HasErrors SQL Injection - Authentication Bypass
CRITICALVERIFIEDby DhiyaneshDK,princechaddha
Shodan: title:"WhatsUp Gold" http.favicon.hash:-2107233094

Scores

CVSS v3 9.8
EPSS 0.9447
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2024-09-16
VulnCheck KEV 2024-09-12
InTheWild.io 2024-09-16
ENISA EUVD EUVD-2024-48017
Ransomware Use Confirmed
CWE
CWE-89
Status published
Products (1)
progress/whatsup_gold < 24.0
Published Aug 29, 2024
KEV Added Sep 16, 2024
Tracked Since Feb 18, 2026