Progress

Whatsup Gold

62 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.44%
  • Veröffentlicht 12.08.2026 15:23:54
  • Zuletzt bearbeitet 02.09.2026 18:25:50

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.

  • EPSS 0.21%
  • Veröffentlicht 12.08.2026 15:23:27
  • Zuletzt bearbeitet 02.09.2026 18:25:58

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.

  • EPSS 0.24%
  • Veröffentlicht 12.08.2026 15:23:07
  • Zuletzt bearbeitet 02.09.2026 18:26:07

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.

  • EPSS 0.16%
  • Veröffentlicht 12.08.2026 15:22:44
  • Zuletzt bearbeitet 02.09.2026 18:26:11

In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.

  • EPSS 0.24%
  • Veröffentlicht 12.08.2026 15:21:55
  • Zuletzt bearbeitet 02.09.2026 18:28:20

In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content.

  • EPSS 0.25%
  • Veröffentlicht 14.04.2025 16:06:45
  • Zuletzt bearbeitet 17.07.2025 14:41:45

In WhatsUp Gold versions released before 2024.0.3, a database manipulation vulnerability allows an unauthenticated attacker to modify the contents of WhatsUp.dbo.WrlsMacAddressGroup.

  • EPSS 6.8%
  • Veröffentlicht 31.12.2024 11:15:06
  • Zuletzt bearbeitet 06.01.2025 16:51:11

In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.

  • EPSS 9.68%
  • Veröffentlicht 31.12.2024 11:15:06
  • Zuletzt bearbeitet 06.01.2025 16:54:14

In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.

  • EPSS 42.37%
  • Veröffentlicht 31.12.2024 11:15:06
  • Zuletzt bearbeitet 08.01.2025 14:15:25

In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclosure.

  • EPSS 9.74%
  • Veröffentlicht 02.12.2024 15:15:12
  • Zuletzt bearbeitet 09.12.2024 20:25:23

In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an existing registry value in registry path HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\.