vulnerability

Progress WhatsUp Gold Vulnerability (CVE-2024-5019): Arbitrary File Read

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
Jun 25, 2024
Added
Jun 27, 2024
Modified
Aug 23, 2024

Description

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Arbitrary File Read issue in Progress WhatsUp Gold. The Wug.UI.Areas.Wug.Controllers.SessionController.CachedCSS vulnerability allows the reading of any file with iisapppool\NmConsole privileges.

Solution

progress-whatsup-gold-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.