Record summary

CVE-2024-6671 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 12, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 24, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: affected

VulnCheck, CVE List2023.1.0 to < 2024.0.0affected

Default status: affected

CVE List2023.1.0 to < 2024.0.0affected

Nuclei templates

1
ProjectDiscoveryCRITICALWhatsUp Gold GetStatisticalMonitorList SQL Injection - Authentication BypassCVSS 9.8

In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

Impact

Unauthenticated attackers can exploit SQL injection to retrieve encrypted user passwords, modify admin credentials, and achieve authentication bypass for full system access.

Remediation

Update WhatsUp Gold to version 2024.0.0 or later to address the SQL injection vulnerability.

WeaknessesCWE-89
Authorsdaffainfo, jjcho
Template tagscvecve2024whatsup-goldauth-bypasssqliintrusivevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:progress:whatsup_gold:*:*:*:*:*:*:*:*
Shodan: title:"WhatsUp Gold" http.favicon.hash:-2107233094

Source: ProjectDiscovery

References

3