Progress

Whatsup Gold

56 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.05%
  • Veröffentlicht 24.10.2024 21:15:15
  • Zuletzt bearbeitet 30.10.2024 14:13:45

In WhatsUp Gold versions released before 2024.0.0,  an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credentials.

Warnung
  • EPSS 94.47%
  • Veröffentlicht 29.08.2024 22:15:05
  • Zuletzt bearbeitet 17.09.2024 01:00:01

In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

  • EPSS 3.6%
  • Veröffentlicht 29.08.2024 22:15:05
  • Zuletzt bearbeitet 04.09.2024 15:53:07

In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

  • EPSS 0.96%
  • Veröffentlicht 29.08.2024 22:15:05
  • Zuletzt bearbeitet 04.09.2024 14:23:58

In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an authenticated low-privileged attacker to achieve privilege escalation by modifying a privileged user's password.

  • EPSS 0.16%
  • Veröffentlicht 25.06.2024 21:16:01
  • Zuletzt bearbeitet 21.11.2024 09:46:47

In WhatsUp Gold versions released before 2023.1.3,  an unauthenticated Arbitrary File Read issue exists in Wug.UI.Areas.Wug.Controllers.SessionController.CachedCSS. This vulnerability allows reading of any file with iisapppool\NmConsole privileges.

  • EPSS 0.16%
  • Veröffentlicht 25.06.2024 21:16:01
  • Zuletzt bearbeitet 21.11.2024 09:46:47

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Path Traversal vulnerability exists Wug.UI.Areas.Wug.Controllers.SessionController.LoadNMScript. This allows allows reading of any file from the applications web-root directory .

Exploit
  • EPSS 0.76%
  • Veröffentlicht 25.06.2024 21:16:01
  • Zuletzt bearbeitet 21.11.2024 09:46:47

In WhatsUp Gold versions released before 2023.1.3, a path traversal vulnerability exists. A specially crafted unauthenticated HTTP request to AppProfileImport can lead can lead to information disclosure.

  • EPSS 5.13%
  • Veröffentlicht 25.06.2024 21:16:01
  • Zuletzt bearbeitet 21.11.2024 09:46:47

In WhatsUp Gold versions released before 2023.1.3, Distributed Edition installations can be exploited by using a deserialization tool to achieve a Remote Code Execution as SYSTEM.  The vulnerability exists in the main message processing routines NmDi...

  • EPSS 0.07%
  • Veröffentlicht 25.06.2024 21:16:00
  • Zuletzt bearbeitet 21.11.2024 09:46:47

In WhatsUp Gold versions released before 2023.1.3, an authenticated SSRF vulnerability in Wug.UI.Areas.Wug.Controllers.SessionControler.Update allows a low privileged user to chain this SSRF with an Improper Access Control vulnerability. This can be ...

  • EPSS 0.07%
  • Veröffentlicht 25.06.2024 21:16:00
  • Zuletzt bearbeitet 21.11.2024 09:46:47

In WhatsUp Gold versions released before 2023.1.3, a Server Side Request Forgery vulnerability exists in the GetASPReport feature. This allows any authenticated user to retrieve ASP reports from an HTML form.