CVE-2024-46909
- EPSS 49.17%
- Veröffentlicht 02.12.2024 15:15:12
- Zuletzt bearbeitet 10.12.2024 18:10:35
In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.
CVE-2024-46905
- EPSS 2.26%
- Veröffentlicht 02.12.2024 15:15:11
- Zuletzt bearbeitet 03.12.2024 20:00:17
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated lower-privileged user (at least Network Manager permissions required) to achieve privilege escalation to the admin account.
CVE-2024-46906
- EPSS 40.58%
- Veröffentlicht 02.12.2024 15:15:11
- Zuletzt bearbeitet 06.12.2024 21:51:59
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.
CVE-2024-46908
- EPSS 2.26%
- Veröffentlicht 02.12.2024 15:15:11
- Zuletzt bearbeitet 10.12.2024 18:23:09
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.
CVE-2024-46907
- EPSS 2.26%
- Veröffentlicht 02.12.2024 15:15:11
- Zuletzt bearbeitet 10.12.2024 18:23:41
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.
CVE-2024-7763
- EPSS 0.61%
- Veröffentlicht 24.10.2024 21:15:15
- Zuletzt bearbeitet 30.10.2024 14:13:45
In WhatsUp Gold versions released before 2024.0.0, an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credentials.
CVE-2024-6672
- EPSS 0.71%
- Veröffentlicht 29.08.2024 22:15:05
- Zuletzt bearbeitet 04.09.2024 14:23:58
In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an authenticated low-privileged attacker to achieve privilege escalation by modifying a privileged user's password.
CVE-2024-6671
- EPSS 14.89%
- Veröffentlicht 29.08.2024 22:15:05
- Zuletzt bearbeitet 04.09.2024 15:53:07
In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.
CVE-2024-6670
- EPSS 94.66%
- Veröffentlicht 29.08.2024 22:15:05
- Zuletzt bearbeitet 31.10.2025 21:54:53
In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.
CVE-2024-5017
- EPSS 1.64%
- Veröffentlicht 25.06.2024 21:16:01
- Zuletzt bearbeitet 21.11.2024 09:46:47
In WhatsUp Gold versions released before 2023.1.3, a path traversal vulnerability exists. A specially crafted unauthenticated HTTP request to AppProfileImport can lead can lead to information disclosure.