CVE-2024-6670
CRITICAL KEV RANSOMWARE NUCLEIWhatsUp Gold SQL Injection (CVE-2024-6670)
Title source: metasploitDescription
In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.
Exploits (2)
metasploit
WORKING POC
by Michael Heinzl, Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam) · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/whatsup_gold_sqli.rb
Nuclei Templates (1)
WhatsUp Gold HasErrors SQL Injection - Authentication Bypass
CRITICALVERIFIEDby DhiyaneshDK,princechaddha
Shodan:
title:"WhatsUp Gold" http.favicon.hash:-2107233094
Scores
CVSS v3
9.8
EPSS
0.9447
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2024-09-16
VulnCheck KEV
2024-09-12
InTheWild.io
2024-09-16
ENISA EUVD
EUVD-2024-48017
Ransomware Use
Confirmed
CWE
CWE-89
Status
published
Products (1)
progress/whatsup_gold
< 24.0
Published
Aug 29, 2024
KEV Added
Sep 16, 2024
Tracked Since
Feb 18, 2026