PT-2022-26514 · Ipswitch · Ipswitch Whatsup Gold

Published

2022-10-12

·

Updated

2025-05-15

·

CVE-2022-42711

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ipswitch WhatsUp Gold versions prior to 22.1.0
Description The issue is related to the SNMP MIB Walker application endpoint, which failed to properly sanitize malicious input. This could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.
Recommendations For versions prior to 22.1.0, update to version 22.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the SNMP MIB Walker application endpoint to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-42711

Affected Products

Ipswitch Whatsup Gold