Progress

Whatsup Gold

62 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.51%
  • Veröffentlicht 14.12.2023 16:15:53
  • Zuletzt bearbeitet 21.11.2024 08:43:42

In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified. It is possible for an attacker to craft a XSS payload and store that value within a device group.   If a WhatsUp Gold user inte...

  • EPSS 0.51%
  • Veröffentlicht 14.12.2023 16:15:52
  • Zuletzt bearbeitet 21.11.2024 08:43:42

In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified.  It is possible for an attacker to craft a XSS payload and store that value within a dashboard component.   If a WhatsUp Gold use...

  • EPSS 2.13%
  • Veröffentlicht 23.06.2023 20:15:09
  • Zuletzt bearbeitet 21.11.2024 08:08:39

In Progress WhatsUp Gold before 23.0.0, an SNMP-related application endpoint failed to adequately sanitize malicious input. This could allow an unauthenticated attacker to execute arbitrary code in a victim's browser, aka XSS.

  • EPSS 1.07%
  • Veröffentlicht 12.10.2022 01:15:11
  • Zuletzt bearbeitet 15.05.2025 18:15:32

In Progress WhatsUp Gold before 22.1.0, an SNMP MIB Walker application endpoint failed to adequately sanitize malicious input. This could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.

  • EPSS 56.83%
  • Veröffentlicht 11.05.2022 18:15:29
  • Zuletzt bearbeitet 21.11.2024 06:59:48

In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to invoke an API transaction that would allow them to relay encrypted WhatsUp Gold user credentials to an arbitrary host.

  • EPSS 4.03%
  • Veröffentlicht 11.05.2022 18:15:29
  • Zuletzt bearbeitet 21.11.2024 06:59:48

In Progress Ipswitch WhatsUp Gold 21.1.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke an API transaction that would allow them to read the contents of a local file.

  • EPSS 5.28%
  • Veröffentlicht 11.05.2022 18:15:29
  • Zuletzt bearbeitet 21.11.2024 06:59:48

In Progress Ipswitch WhatsUp Gold 16.1 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to obtain the WhatsUp Gold installation serial number.

  • EPSS 3.62%
  • Veröffentlicht 11.05.2022 18:15:29
  • Zuletzt bearbeitet 21.11.2024 06:59:48

In Progress Ipswitch WhatsUp Gold 17.0.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke an API transaction that would allow them to read sensitive operating-system attributes from a host that is accessible by the Whats...

Exploit
  • EPSS 5.88%
  • Veröffentlicht 28.09.2021 18:15:09
  • Zuletzt bearbeitet 25.09.2026 16:48:10

In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input. which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.

  • EPSS 1.44%
  • Veröffentlicht 01.05.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 04:14:38

An SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can submit specially crafted requests via the NmAPI executable to (1) gain unauthorized access to the WhatsUp Gold system, (2) obtain information ...